diff --git a/.gitignore b/.gitignore index 7f4949c..58fc5b0 100644 --- a/.gitignore +++ b/.gitignore @@ -2,4 +2,6 @@ *.vscode *.env *artifacts* -*k8s-admin* \ No newline at end of file +*k8s-admin* +*vault-keys.json* +*config.yaml* \ No newline at end of file diff --git a/cmd/main/main.go b/cmd/main/main.go index 4b2184b..974d767 100644 --- a/cmd/main/main.go +++ b/cmd/main/main.go @@ -9,23 +9,23 @@ import ( ) func parseArgs() (string, string, string) { - var password, configPath, dataDir string + var password, configPath, workDir string flag.StringVar(&password, "p", "", "Password to access hosts") flag.StringVar(&configPath, "c", "/etc/kube-forge/config.yaml", "Path to config file") - flag.StringVar(&dataDir, "d", "/var/lib/kube-forge", "Path to data dir") + flag.StringVar(&workDir, "d", "/var/lib/kube-forge", "Path to kube-forge work dir") flag.Parse() - return password, configPath, dataDir + return password, configPath, workDir } func main() { - password, configPath, dataDir := parseArgs() - config := config.CreateConfig(configPath, dataDir, password) + password, configPath, workDir := parseArgs() + config := config.CreateConfig(configPath, workDir, password) repositories, releases := templates.GetHelmAppsConfigData() config.Repositories = repositories config.Releases = releases - templates.ApplyTemplates() + templates.ApplyK8sTemplates() for _, cmd := range os.Args { switch cmd { diff --git a/config.sample.yaml b/config.sample.yaml new file mode 100644 index 0000000..df671ac --- /dev/null +++ b/config.sample.yaml @@ -0,0 +1,292 @@ +credentials: + user: sre-admin + ask_sudo_password: false + private_key_file: /home/sre-admin/.ssh/id_rsa + +hosts: + - hostname: vbox-prod-k8s-master-01 + ip: "10.250.50.22" + roles: [control_plane, etcd] + + # # Optional creds for each host + # user: user + # password: nF5S8nuKi87Dh42Jnjik + + - hostname: vbox-prod-k8s-slave-01 + ip: "10.250.50.23" + roles: [node] + + - hostname: vbox-prod-k8s-slave-02 + ip: "10.250.50.21" + roles: [node] + +orchestrator: + version: v1.29.0 + cluster_name: k8s-cluster.local + # bin_dir: /usr/local/bin + # sysctl_file_path: /etc/sysctl.d/99-sysctl.conf + loadbalancer_apiserver_port: 6443 + dns: + servers: + - 8.8.8.8 + - 8.8.4.4 + disable_host_nameservers: false + # cloud_provider: "" # 'gce', 'aws', 'azure', 'openstack', 'vsphere', 'oci', or 'external' + # external_cloud_provider: "" # 'openstack', 'vsphere' and 'hcloud' + + container_engine: + type: containerd # docker, crio and containerd + install: true + + ping_access_ip: true + auto_renew_certificates: true + event_ttl: "1h0m0s" + pod_security_policy_enabled: true + + network: + plugin: calico # cilium, calico, kube-ovn, weave or flannel + # service_addresses: 10.233.0.0/18 + # pods_subnet: 10.233.64.0/18 + +modules: + admin_password: changeit + + ## Add additional helm repositories before installation + # additional_repositories: + # - name: argo-helm + # url: "https://argoproj.github.io/argo-helm" + + observability: + enabled: true + + logging: + enabled: true + + loki: + persistence: + storage_size: 10Gi + retention: 168h + + events: + enabled: true + cron: + schedule: "*/2 * * * *" + + tracing: + enabled: true + + tempo: + retention: 24h + listen_port: 3100 + + persistence: + storage_size: 10Gi + + tempo_query: + listen_port: 16686 + + monitoring: + enabled: true + + prometheus: + scrape_interval: 15s + persistence: + storage_size: 3Gi + retention: 7d + + alert_manager: + enabled: true + # additionalMessageTemplates: {} + + route: + receiver: kvazaric_notifications + group_wait: 1s + repeat_interval: 180m + + routes: + - receiver: "kvazaric_notifications" + group_by: ["alertname"] + group_wait: 1s + repeat_interval: 8737h + matchers: + - fireOnce=true + receivers: + - name: kvazaric_notifications + telegram_configs: + - send_resolved: true + api_url: https://api.telegram.org + bot_token: bot_token + chat_id: chat_id # int + parse_mode: HTML + message: '{% raw %}{{ "{{" }} template "default-message" . {{ "}}" }}{% endraw %}' + http_config: + follow_redirects: true + enable_http2: false + + blackbox: + enabled: true + additional_modules: | + + kube_state: + enabled: true + + node: + enabled: true + + visualization: + enabled: true + + grafana: + enabled: true + expose: + type: ingress # ingress or NodePort + domain: grafana.disk.lt.t1.cloud + node_port_http: 30007 + + tls: + enabled: true + + persistence: + storage_size: 2Gi + + cicd: + enabled: true + + argo_cd: + expose: + type: ingress # ingress or NodePort + domain: argocd.disk.lt.t1.cloud + + node_port_http: 30005 + node_port_https: 30006 + + tls: + enabled: true + + repositories: + {} + # harbor-helm: + # enableOCI: "true" + # type: helm + # name: helm-mountbit + # url: harbor.disk.t1.cloud/mountbit-helm + # username: username + # password: password + rbac: + additional_policies: | + p, developer, applications, *, */*, allow + + p, developer, applications, *, */*logging*, deny + p, developer, repositories, get, *, allow + p, developer, projects, get, *, allow + + p, developer, logs, get, *, allow + + p, guest, applications, get, */*, allow + p, guest, projects, get, *, allow + + ha: + enabled: false + autoscaling: false + + rollouts: + enabled: true + + updates_operator: + enabled: true + + secrets_storage: + enabled: true + key_shares: 5 + key_threshold: 3 + + # specify unseal keys to auto-unseal after updates or restarts + unseal_keys: + - "abc" + - "abc" + - "abc" + expose: + type: ingress # ingress or NodePort + domain: vault.disk.lt.t1.cloud + node_port: 30004 + + tls: + enabled: true + + # requires secrets_store_csi_driver in additional modules + csi_integration: + enabled: true + agent: + image: hashicorp/vault + tag: 1.16.0 + server: + image: "hashicorp/vault" + tag: 1.16.0 + persistence: + size: 10Gi + + registry: + enabled: true + expose: + type: ingress # ingress or nodePort + # if expose_type is "ingress" + domain: harbor.disk.lt.t1.cloud + + # if expose_type is "NodePort" + node_port_http: 30002 + node_port_https: 30003 + tls: + enabled: true + + persistence: + registry_size: 10Gi + jobservice_size: 1Gi + database_size: 2Gi + redis_size: 1Gi + trivy_size: 5Gi + + defaultProjects: + - name: harbor-helm + public: false + enabled_scanner: true + + additional: + cert_manager: + enabled: true + ha_enabled: false + dns_servers: + - "1.1.1.1" + - "8.8.8.8" + account_email: reversstorm@gmail.com + + ingress: + type: nginx # nginx + enabled: true + ingress_class_name: nginx + host_network: true + + # load_balancer: + # type: metallb + # install: true + + # docker_secrets: + # repositories: + # - name: registry + # repository: registry.example.com + # username: admin + # password: admin + # namespaces: + # - default + + storage: + local_path_provisioner: + storage_class_name: local-path + reclaim_policy: Delete + + longhorn: + enabled: true + + secrets_store_csi_driver: + enabled: true + + ## TODO: ceph diff --git a/config.yaml b/config.yaml index ef07af2..22c9a82 100644 --- a/config.yaml +++ b/config.yaml @@ -197,6 +197,14 @@ modules: secrets_storage: enabled: true + key_shares: 5 + key_threshold: 3 + + # specify unseal keys to auto-unseal after updates or restarts + unseal_keys: + - "8gSX9uR1P0ypMlHN2YSwbARACE/VzBU3nF7Pg3M6mWzj" + - "XV2MmiPbbiWpp0uzfDUTlPqtDfF8Z/HlrZKbHDZXZiGO" + - "b3EPh7JxDLeAgXj6oMxdZronEiJ3ef9KJDazsaibD3TB" expose: type: ingress # ingress or NodePort domain: vault.disk.lt.t1.cloud @@ -208,17 +216,12 @@ modules: # requires secrets_store_csi_driver in additional modules csi_integration: enabled: true - image: hashicorp/vault-csi-provider - version: 1.4.1 agent: image: hashicorp/vault - version: 1.15.6 - injector: - image: hashicorp/vault-k8s - version: 1.3.1 + tag: 1.16.0 server: image: "hashicorp/vault" - version: 1.15.6 + tag: 1.16.0 persistence: size: 10Gi diff --git a/go.mod b/go.mod index 84d178e..a472e82 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module kube-forge -go 1.22 +go 1.22.0 toolchain go1.22.2 @@ -20,24 +20,60 @@ require ( github.com/apenella/go-common-utils/data v0.0.0-20220913191136-86daaa87e7df // indirect github.com/apenella/go-common-utils/error v0.0.0-20220913191136-86daaa87e7df // indirect github.com/davecgh/go-spew v1.1.1 // indirect + github.com/emicklei/go-restful/v3 v3.11.0 // indirect github.com/fatih/color v1.16.0 // indirect - github.com/google/uuid v1.1.1 // indirect + github.com/go-logr/logr v1.4.1 // indirect + github.com/go-openapi/jsonpointer v0.19.6 // indirect + github.com/go-openapi/jsonreference v0.20.2 // indirect + github.com/go-openapi/swag v0.22.3 // indirect + github.com/gogo/protobuf v1.3.2 // indirect + github.com/golang/protobuf v1.5.4 // indirect + github.com/google/gnostic-models v0.6.8 // indirect + github.com/google/go-cmp v0.6.0 // indirect + github.com/google/gofuzz v1.2.0 // indirect + github.com/google/uuid v1.3.0 // indirect + github.com/gorilla/websocket v1.5.0 // indirect github.com/huandu/xstrings v1.3.3 // indirect github.com/imdario/mergo v0.3.11 // indirect github.com/joho/godotenv v1.5.1 // indirect - github.com/kr/pretty v0.2.1 // indirect + github.com/josharian/intern v1.0.0 // indirect + github.com/json-iterator/go v1.1.12 // indirect + github.com/kr/pretty v0.3.1 // indirect + github.com/mailru/easyjson v0.7.7 // indirect github.com/mattn/go-colorable v0.1.13 // indirect github.com/mattn/go-isatty v0.0.20 // indirect github.com/mitchellh/copystructure v1.0.0 // indirect github.com/mitchellh/reflectwalk v1.0.0 // indirect + github.com/moby/spdystream v0.2.0 // indirect + github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect + github.com/modern-go/reflect2 v1.0.2 // indirect + github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect + github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect github.com/pkg/errors v0.9.1 // indirect github.com/pmezard/go-difflib v1.0.0 // indirect github.com/shopspring/decimal v1.2.0 // indirect github.com/spf13/cast v1.3.1 // indirect + github.com/spf13/pflag v1.0.5 // indirect github.com/stretchr/objx v0.5.2 // indirect github.com/stretchr/testify v1.9.0 // indirect + golang.org/x/net v0.24.0 // indirect + golang.org/x/oauth2 v0.10.0 // indirect golang.org/x/sys v0.19.0 // indirect + golang.org/x/term v0.19.0 // indirect + golang.org/x/text v0.14.0 // indirect + golang.org/x/time v0.3.0 // indirect + google.golang.org/appengine v1.6.7 // indirect + google.golang.org/protobuf v1.33.0 // indirect + gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/yaml.v2 v2.4.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect + k8s.io/api v0.30.0 // indirect + k8s.io/apimachinery v0.30.0 // indirect + k8s.io/client-go v0.30.0 // indirect + k8s.io/klog/v2 v2.120.1 // indirect + k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340 // indirect + k8s.io/utils v0.0.0-20230726121419-3b25d923346b // indirect olympos.io/encoding/edn v0.0.0-20201019073823-d3554ca0b0a3 // indirect + sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect + sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect ) diff --git a/go.sum b/go.sum index 38e5fc7..31a073b 100644 --- a/go.sum +++ b/go.sum @@ -14,17 +14,43 @@ github.com/apenella/go-common-utils/data v0.0.0-20220913191136-86daaa87e7df h1:s github.com/apenella/go-common-utils/data v0.0.0-20220913191136-86daaa87e7df/go.mod h1:cLVL6GjUiKG/WyBzX+KD6h/XRV/HnNZIZbMNNiBgQ9o= github.com/apenella/go-common-utils/error v0.0.0-20220913191136-86daaa87e7df h1:SvlYbjlsSQDS7hbVT1h012/zdgvcwWJ+Yd9XRiiY/8s= github.com/apenella/go-common-utils/error v0.0.0-20220913191136-86daaa87e7df/go.mod h1:+3dyIlHX350xJIUIffwMLswZXU+N2FwDE05VuKqxYdw= +github.com/creack/pty v1.1.9/go.mod h1:oKZEueFk5CKHvIhNR5MUki03XCEU+Q6VDXinZuGJ33E= github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/emicklei/go-restful/v3 v3.11.0 h1:rAQeMHw1c7zTmncogyy8VvRZwtkmkZ4FxERmMY4rD+g= +github.com/emicklei/go-restful/v3 v3.11.0/go.mod h1:6n3XBCmQQb25CM2LCACGz8ukIrRry+4bhvbpWn3mrbc= github.com/fatih/color v1.16.0 h1:zmkK9Ngbjj+K0yRhTVONQh1p/HknKYSlNT+vZCzyokM= github.com/fatih/color v1.16.0/go.mod h1:fL2Sau1YI5c0pdGEVCbKQbLXB6edEj1ZgiY4NijnWvE= github.com/go-errors/errors v1.5.1 h1:ZwEMSLRCapFLflTpT7NKaAc7ukJ8ZPEjzlxt8rPN8bk= github.com/go-errors/errors v1.5.1/go.mod h1:sIVyrIiJhuEF+Pj9Ebtd6P/rEYROXFi3BopGUQ5a5Og= -github.com/google/go-cmp v0.5.9 h1:O2Tfq5qg4qc4AmwVlvv0oLiVAGB7enBSJ2x2DqQFi38= +github.com/go-logr/logr v1.4.1 h1:pKouT5E8xu9zeFC39JXRDukb6JFQPXM5p5I91188VAQ= +github.com/go-logr/logr v1.4.1/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= +github.com/go-openapi/jsonpointer v0.19.6 h1:eCs3fxoIi3Wh6vtgmLTOjdhSpiqphQ+DaPn38N2ZdrE= +github.com/go-openapi/jsonpointer v0.19.6/go.mod h1:osyAmYz/mB/C3I+WsTTSgw1ONzaLJoLCyoi6/zppojs= +github.com/go-openapi/jsonreference v0.20.2 h1:3sVjiK66+uXK/6oQ8xgcRKcFgQ5KXa2KvnJRumpMGbE= +github.com/go-openapi/jsonreference v0.20.2/go.mod h1:Bl1zwGIM8/wsvqjsOQLJ/SH+En5Ap4rVB5KVcIDZG2k= +github.com/go-openapi/swag v0.22.3 h1:yMBqmnQ0gyZvEb/+KzuWZOXgllrXT4SADYbvDaXHv/g= +github.com/go-openapi/swag v0.22.3/go.mod h1:UzaqsxGiab7freDnrUUra0MwWfN/q7tE4j+VcZ0yl14= +github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q= +github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q= +github.com/golang/protobuf v1.3.1/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U= +github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek= +github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps= +github.com/google/gnostic-models v0.6.8 h1:yo/ABAfM5IMRsS1VnXjTBvUb61tFIHozhlYvRgGre9I= +github.com/google/gnostic-models v0.6.8/go.mod h1:5n7qKqH0f5wFt+aWF8CW6pZLLNOfYuF5OpfBSENuI8U= github.com/google/go-cmp v0.5.9/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= -github.com/google/uuid v1.1.1 h1:Gkbcsh/GbpXz7lPftLA3P6TYMwjCLYm83jiFQZF/3gY= +github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI= +github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= +github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= +github.com/google/gofuzz v1.2.0 h1:xRy4A+RhZaiKjJ1bPfwQ8sedCA+YS2YcCHW6ec7JMi0= +github.com/google/gofuzz v1.2.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= github.com/google/uuid v1.1.1/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= +github.com/google/uuid v1.3.0 h1:t6JiXgmwXMjEs8VusXIJk2BXHsn+wx8BZdTaoZ5fu7I= +github.com/google/uuid v1.3.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= +github.com/gorilla/websocket v1.4.2/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/adAjf1fMHhE= +github.com/gorilla/websocket v1.5.0 h1:PPwGk2jz7EePpoHN/+ClbZu8SPxiqlu12wZP/3sWmnc= +github.com/gorilla/websocket v1.5.0/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/adAjf1fMHhE= github.com/huandu/xstrings v1.3.3 h1:/Gcsuc1x8JVbJ9/rlye4xZnVAbEkGauT8lbebqcQws4= github.com/huandu/xstrings v1.3.3/go.mod h1:y5/lhBue+AyNmUVz9RLU9xbLR0o4KIIExikq4ovT0aE= github.com/ilyakaznacheev/cleanenv v1.5.0 h1:0VNZXggJE2OYdXE87bfSSwGxeiGt9moSR2lOrsHHvr4= @@ -33,12 +59,21 @@ github.com/imdario/mergo v0.3.11 h1:3tnifQM4i+fbajXKBHXWEH+KvNHqojZ778UH75j3bGA= github.com/imdario/mergo v0.3.11/go.mod h1:jmQim1M+e3UYxmgPu/WyfjB3N3VflVyUjjjwH0dnCYA= github.com/joho/godotenv v1.5.1 h1:7eLL/+HRGLY0ldzfGMeQkb7vMd0as4CfYvUVzLqw0N0= github.com/joho/godotenv v1.5.1/go.mod h1:f4LDr5Voq0i2e/R5DDNOoa2zzDfwtkZa6DnEwAbqwq4= +github.com/josharian/intern v1.0.0 h1:vlS4z54oSdjm0bgjRigI+G1HpF+tI+9rE5LLzOg8HmY= +github.com/josharian/intern v1.0.0/go.mod h1:5DoeVV0s6jJacbCEi61lwdGj/aVlrQvzHFFd8Hwg//Y= +github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM= +github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo= +github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8= +github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck= github.com/kr/pretty v0.2.1 h1:Fmg33tUaq4/8ym9TJN1x7sLJnHVwhP33CNkpYV/7rwI= github.com/kr/pretty v0.2.1/go.mod h1:ipq/a2n7PKx3OHsz4KJII5eveXtPO4qwEXGdVfWzfnI= +github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ= github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE= +github.com/mailru/easyjson v0.7.7 h1:UGYAvKxe3sBsEDzO8ZeWOSlIQfWFlxbzLZe7hwFURr0= +github.com/mailru/easyjson v0.7.7/go.mod h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc= github.com/mattn/go-colorable v0.1.13 h1:fFA4WZxdEF4tXPZVKMLwD8oUnCTTo08duU7wxecdEvA= github.com/mattn/go-colorable v0.1.13/go.mod h1:7S9/ev0klgBDR4GtXTXX8a3vIGJpMovkB8vQcUbaXHg= github.com/mattn/go-isatty v0.0.16/go.mod h1:kYGgaQfpe5nmfYZH+SKPsOc2e4SrIfOl2e/yFXSvRLM= @@ -48,37 +83,76 @@ github.com/mitchellh/copystructure v1.0.0 h1:Laisrj+bAB6b/yJwB5Bt3ITZhGJdqmxquMK github.com/mitchellh/copystructure v1.0.0/go.mod h1:SNtv71yrdKgLRyLFxmLdkAbkKEFWgYaq1OVrnRcwhnw= github.com/mitchellh/reflectwalk v1.0.0 h1:9D+8oIskB4VJBN5SFlmc27fSlIBZaov1Wpk/IfikLNY= github.com/mitchellh/reflectwalk v1.0.0/go.mod h1:mSTlrgnPZtwu0c4WaC2kGObEpuNDbx0jmZXqmk4esnw= +github.com/moby/spdystream v0.2.0 h1:cjW1zVyyoiM0T7b6UoySUFqzXMoqRckQtXwGPiBhOM8= +github.com/moby/spdystream v0.2.0/go.mod h1:f7i0iNDQJ059oMTcWxx8MA/zKFIuD/lY+0GqbN2Wy8c= +github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q= +github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd h1:TRLaZ9cD/w8PVh93nsPXa1VrQ6jlwL5oN8l14QlcNfg= +github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q= +github.com/modern-go/reflect2 v1.0.2 h1:xBagoLtFs94CBntxluKeaWgTMpvLxC4ur3nMaC9Gz0M= +github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk= +github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA= +github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ= +github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f h1:y5//uYreIhSUg3J1GEMiLbxo1LJaP8RfCpH6pymGZus= +github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f/go.mod h1:ZdcZmHo+o7JKHSa8/e818NopupXU1YMK5fe1lsApnBw= +github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e/go.mod h1:pJLUxLENpZxwdsKMEsNbx1VGcRFpLqf3715MtcvvzbA= github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4= github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= +github.com/rogpeppe/go-internal v1.9.0/go.mod h1:WtVeX8xhTBvf0smdhujwtBcq4Qrzq/fJaraNFVN+nFs= github.com/shopspring/decimal v1.2.0 h1:abSATXmQEYyShuxI4/vyW3tV1MrKAJzCZ/0zLUXYbsQ= github.com/shopspring/decimal v1.2.0/go.mod h1:DKyhrW/HYNuLGql+MJL6WCR6knT2jwCFRcu2hWCYk4o= github.com/sosedoff/ansible-vault-go v0.2.0 h1:XqkBdqbXgTuFQ++NdrZvSdUTNozeb6S3V5x7FVs17vg= github.com/sosedoff/ansible-vault-go v0.2.0/go.mod h1:wMU54HNJfY0n0KIgbpA9m15NBfaUDlJrAsaZp0FwzkI= github.com/spf13/cast v1.3.1 h1:nFm6S0SMdyzrzcmThSipiEubIDy8WEXKNZ0UOgiRpng= github.com/spf13/cast v1.3.1/go.mod h1:Qx5cxh0v+4UWYiBimWS+eyWzqEqokIECu5etghLkUJE= +github.com/spf13/pflag v1.0.5 h1:iy+VFUOCP1a+8yFto/drg2CJ5u0yRoB7fZw3DKv/JXA= +github.com/spf13/pflag v1.0.5/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= +github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw= +github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo= github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY= github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA= github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs= +github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= github.com/stretchr/testify v1.5.1/go.mod h1:5W2xD1RspED5o8YsWQXVCued0rvSQ+mT+I5cxcmMvtA= +github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= +github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU= +github.com/stretchr/testify v1.8.1/go.mod h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4= github.com/stretchr/testify v1.9.0 h1:HtqpIVDClZ4nwg75+f6Lvsy/wHu+3BoSGCbBAcpTsTg= github.com/stretchr/testify v1.9.0/go.mod h1:r2ic/lqez/lEtzL7wO/rwa5dbSLXVDPFyf8C91i36aY= +github.com/yuin/goldmark v1.1.27/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= +github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= +golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= +golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto= golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= golang.org/x/crypto v0.3.0/go.mod h1:hebNnKkNXi2UzZN1eVRvBB7co0a+JxK6XbPiWVs/3J4= golang.org/x/crypto v0.22.0 h1:g1v0xeRhjcugydODzvb3mEM9SQ0HGp9s/nh3COQ/C30= golang.org/x/crypto v0.22.0/go.mod h1:vr6Su+7cTlO45qkww3VDJlzDn0ctJvRgYbC2NvXHt+M= +golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= +golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= +golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= +golang.org/x/net v0.0.0-20190603091049-60506f45cf65/go.mod h1:HSz+uSET+XFnRR8LxR5pz3Of3rY3CfYBVs4xY44aLks= golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= golang.org/x/net v0.2.0/go.mod h1:KqCZLdyyvdV855qA2rE3GC2aiw5xGR5TEjj8smXukLY= +golang.org/x/net v0.24.0 h1:1PcaxkF854Fu3+lvBIx5SYn9wRlBzzcnHZSiaFFAb0w= +golang.org/x/net v0.24.0/go.mod h1:2Q7sJY5mzlzWjKtYUEXSlBWCdyaioyXzRB2RtU8KVE8= +golang.org/x/oauth2 v0.10.0 h1:zHCpF2Khkwy4mMB4bv0U37YtJdTGW8jI0glAApi0Kh8= +golang.org/x/oauth2 v0.10.0/go.mod h1:kTpgurOux7LqtuxjuyZa4Gj2gdezIt/jQtGnNFfypQI= golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= @@ -91,24 +165,60 @@ golang.org/x/sys v0.19.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= golang.org/x/term v0.2.0/go.mod h1:TVmDHMZPmdnySmBfhjOoOdhjzdE1h4u1VwSiw2l1Nuc= +golang.org/x/term v0.19.0 h1:+ThwsDv+tYfnJFhF4L8jITxu1tdTWRTZpdsWgEgjL6Q= +golang.org/x/term v0.19.0/go.mod h1:2CuTdWZ7KHSQwUzKva0cbMg6q2DMI3Mmxp+gKJbskEk= golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= +golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk= golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= golang.org/x/text v0.4.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= +golang.org/x/text v0.14.0 h1:ScX5w1eTa3QqT8oi6+ziP7dTV1S2+ALU0bI+0zXKWiQ= +golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU= +golang.org/x/time v0.3.0 h1:rg5rLMjNzMS1RkNLzCG38eapWhnYLFYXDXj2gOlr8j4= +golang.org/x/time v0.3.0/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE= +golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +google.golang.org/appengine v1.6.7 h1:FZR1q0exgwxzPzp/aF+VccGrSfxfPpkBqjIIEq3ru6c= +google.golang.org/appengine v1.6.7/go.mod h1:8WjMMxjGQR8xUklV/ARdw2HLXBOI7O7uCIDZVag1xfc= +google.golang.org/protobuf v1.33.0 h1:uNO2rsAINq/JlFpSdYEKIZ0uKD/R9cpdv0T+yoGwGmI= +google.golang.org/protobuf v1.33.0/go.mod h1:c6P6GXX6sHbq/GpV6MGZEdwhWPcYBgnhAHhKbcUYpos= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk= gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q= +gopkg.in/inf.v0 v0.9.1 h1:73M5CoZyi3ZLMOyDlQh031Cx6N9NDJ2Vvfl76EDAgDc= +gopkg.in/inf.v0 v0.9.1/go.mod h1:cWUDdTG/fYaXco+Dcufb5Vnc6Gp2YChqWtbxRZE0mXw= gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= +gopkg.in/yaml.v2 v2.2.8/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= gopkg.in/yaml.v2 v2.3.0/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= gopkg.in/yaml.v2 v2.4.0 h1:D8xgwECY7CYvx+Y2n4sBz93Jn9JRvxdiyyo8CTfuKaY= gopkg.in/yaml.v2 v2.4.0/go.mod h1:RDklbk79AGWmwhnvt/jBztapEOGDOx6ZbXqjP6csGnQ= +gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= +k8s.io/api v0.30.0 h1:siWhRq7cNjy2iHssOB9SCGNCl2spiF1dO3dABqZ8niA= +k8s.io/api v0.30.0/go.mod h1:OPlaYhoHs8EQ1ql0R/TsUgaRPhpKNxIMrKQfWUp8QSE= +k8s.io/apimachinery v0.30.0 h1:qxVPsyDM5XS96NIh9Oj6LavoVFYff/Pon9cZeDIkHHA= +k8s.io/apimachinery v0.30.0/go.mod h1:iexa2somDaxdnj7bha06bhb43Zpa6eWH8N8dbqVjTUc= +k8s.io/client-go v0.30.0 h1:sB1AGGlhY/o7KCyCEQ0bPWzYDL0pwOZO4vAtTSh/gJQ= +k8s.io/client-go v0.30.0/go.mod h1:g7li5O5256qe6TYdAMyX/otJqMhIiGgTapdLchhmOaY= +k8s.io/klog/v2 v2.120.1 h1:QXU6cPEOIslTGvZaXvFWiP9VKyeet3sawzTOvdXb4Vw= +k8s.io/klog/v2 v2.120.1/go.mod h1:3Jpz1GvMt720eyJH1ckRHK1EDfpxISzJ7I9OYgaDtPE= +k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340 h1:BZqlfIlq5YbRMFko6/PM7FjZpUb45WallggurYhKGag= +k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340/go.mod h1:yD4MZYeKMBwQKVht279WycxKyM84kkAx2DPrTXaeb98= +k8s.io/utils v0.0.0-20230726121419-3b25d923346b h1:sgn3ZU783SCgtaSJjpcVVlRqd6GSnlTLKgpAAttJvpI= +k8s.io/utils v0.0.0-20230726121419-3b25d923346b/go.mod h1:OLgZIPagt7ERELqWJFomSt595RzquPNLL48iOWgYOg0= olympos.io/encoding/edn v0.0.0-20201019073823-d3554ca0b0a3 h1:slmdOY3vp8a7KQbHkL+FLbvbkgMqmXojpFUO/jENuqQ= olympos.io/encoding/edn v0.0.0-20201019073823-d3554ca0b0a3/go.mod h1:oVgVk4OWVDi43qWBEyGhXgYxt7+ED4iYNpTngSLX2Iw= +sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd h1:EDPBXCAspyGV4jQlpZSudPeMmr1bNJefnuqLsRAsHZo= +sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd/go.mod h1:B8JuhiUyNFVKdsE8h686QcCxMaH6HrOAZj4vswFpcB0= +sigs.k8s.io/structured-merge-diff/v4 v4.4.1 h1:150L+0vs/8DA78h1u02ooW1/fFq/Lwr+sGiqlzvrtq4= +sigs.k8s.io/structured-merge-diff/v4 v4.4.1/go.mod h1:N8hJocpFajUSSeSJ9bOZ77VzejKZaXsTtZo4/u7Io08= sigs.k8s.io/yaml v1.4.0 h1:Mk1wCc2gy/F0THH0TAp1QYyJNzRm2KCLy3o5ASXVI5E= sigs.k8s.io/yaml v1.4.0/go.mod h1:Ejl7/uTz7PSA4eKMyQCUTnhZYNmLIl+5c2lQPGR2BPY= diff --git a/kubespray/inventory/group_vars/k8s_cluster/addons.yml b/kubespray/inventory/group_vars/k8s_cluster/addons.yml index 9475b06..b656a69 100644 --- a/kubespray/inventory/group_vars/k8s_cluster/addons.yml +++ b/kubespray/inventory/group_vars/k8s_cluster/addons.yml @@ -243,15 +243,7 @@ releases: namespace: kube-system chart_ref: kube-forge/docker-secrets-generator chart_version: 0.1.0 - release_state: "present" - values: - repositories: - - name: registry - namespaces: - - default - password: admin - repository: registry.example.com - username: admin + release_state: "absent" - name: longhorn namespace: longhorn-system @@ -4221,7 +4213,7 @@ releases: server.insecure: true secret: - argocdServerAdminPassword: $2a$10$x1v7bUZNu8ua7LIt5AISbe039/4D8kVUAgWvXyeZxmHJXs4V0TWhm + argocdServerAdminPassword: $2a$10$7M.OEGsyvWrf.T4j1R.dK.BuIl75k8JzbSthgl8mCvrhec05Q.ICe repositories: # add default helm-repository from harbor @@ -4785,7 +4777,7 @@ releases: # required. agentImage: repository: "hashicorp/vault" - tag: "1.15.6" + tag: "1.16.0" agentDefaults: cpuLimit: "500m" cpuRequest: "250m" @@ -5012,7 +5004,7 @@ releases: image: repository: "hashicorp/vault" - tag: "1.15.6" + tag: "1.16.0" # Overrides the default Image Pull Policy pullPolicy: IfNotPresent @@ -5063,7 +5055,7 @@ releases: # name: http-monitoring readinessProbe: - enabled: true + enabled: false # If you need to use a http path instead of the default exec # path: /v1/sys/health?standbyok=true @@ -5107,11 +5099,6 @@ releases: # Used to set the sleep time during the preStop step preStopSleepSeconds: 5 - postStart: - # - /bin/sh - # - -c - # - /vault/userconfig/myscript/run.sh - extraEnvironmentVars: {} extraSecretEnvironmentVars: [] @@ -5501,7 +5488,7 @@ releases: image: repository: "hashicorp/vault" - tag: "1.15.6" + tag: "1.16.0" pullPolicy: IfNotPresent logFormat: standard @@ -5516,6 +5503,7 @@ releases: extraLabels: {} readinessProbe: + enabled: true failureThreshold: 2 initialDelaySeconds: 5 periodSeconds: 5 diff --git a/pkg/config/config.go b/pkg/config/config.go index 2d068ff..cd3bd2b 100644 --- a/pkg/config/config.go +++ b/pkg/config/config.go @@ -15,7 +15,7 @@ type Host struct { } type Config struct { - DataDir string + WorkDir string Credentials struct { User string `yaml:"user"` Password string `yaml:"password"` @@ -43,9 +43,9 @@ type Config struct { var instance *Config -func CreateConfig(configPath string, dataDir string, password string) *Config { +func CreateConfig(configPath string, workDir string, password string) *Config { instance = &Config{} - instance.DataDir = dataDir + instance.WorkDir = workDir if err := cleanenv.ReadConfig(configPath, instance); err != nil { helper, _ := cleanenv.GetDescription(instance, nil) diff --git a/pkg/config/kubernetes.go b/pkg/config/kubernetes.go new file mode 100644 index 0000000..b3e2c51 --- /dev/null +++ b/pkg/config/kubernetes.go @@ -0,0 +1,21 @@ +package config + +import ( + "path/filepath" + + "k8s.io/client-go/rest" + "k8s.io/client-go/tools/clientcmd" +) + +var kubernetesConfig *rest.Config + +func GetKubernetesConfig() *rest.Config { + appConfig := GetConfig() + kubeconfigPath := filepath.Join(appConfig.WorkDir, "k8s-admin.conf") + + kubernetesConfig, err := clientcmd.BuildConfigFromFlags("", kubeconfigPath) + if err != nil { + panic(err.Error()) + } + return kubernetesConfig +} diff --git a/pkg/config/modules_secrets_storage.go b/pkg/config/modules_secrets_storage.go index c8d7c0d..8814916 100644 --- a/pkg/config/modules_secrets_storage.go +++ b/pkg/config/modules_secrets_storage.go @@ -1,11 +1,13 @@ package config type SecretsStorage struct { - ChartRef string `yaml:"chart_ref" env-default:"kube-forge/vault"` - ChartVersion string `yaml:"chart_version" env-default:"0.1.0"` - Enabled bool `yaml:"enabled"` - Image string `yaml:"image" env-default:"kubesphere/fluent-operator"` - Tag string `yaml:"tag" env-default:"v2.7.0"` + ChartRef string `yaml:"chart_ref" env-default:"kube-forge/vault"` + ChartVersion string `yaml:"chart_version" env-default:"0.1.0"` + Enabled bool `yaml:"enabled"` + KeyShares int `yaml:"key_shares" env-default:"5"` + KeyThreshold int `yaml:"key_threshold" env-default:"3"` + UnsealKeys []string `yaml:"unseal_keys" env-default:"[]"` + RootToken string Expose struct { Type string `yaml:"type"` Domain string `yaml:"domain"` diff --git a/pkg/kubernetes_client/pod.go b/pkg/kubernetes_client/pod.go new file mode 100644 index 0000000..ea8e1b3 --- /dev/null +++ b/pkg/kubernetes_client/pod.go @@ -0,0 +1,80 @@ +package kubernetes_client + +import ( + "bytes" + "context" + "fmt" + "kube-forge/pkg/config" + "net/http" + "strings" + "time" + + corev1 "k8s.io/api/core/v1" + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/client-go/kubernetes" + "k8s.io/client-go/tools/remotecommand" +) + +func ExecuteCommandInPodContainer(command string, namespace string, podName string, container string) (string, error) { + clientset, err := kubernetes.NewForConfig(config.GetKubernetesConfig()) + if err != nil { + panic(err.Error()) + } + commandArray := strings.Split(command, " ") + + execRequest := clientset.CoreV1().RESTClient().Post(). + Resource("pods"). + Name(podName). + Namespace(namespace). + SubResource("exec"). + Param("container", container). + Param("stderr", "true"). + Param("stdout", "true") + for _, com := range commandArray { + execRequest = execRequest.Param("command", com) + } + + stderr := bytes.NewBufferString("") + stdout := bytes.NewBufferString("") + + streamOptions := remotecommand.StreamOptions{ + Stdout: stdout, + Stderr: stderr, + Tty: false, + } + + exec, err := remotecommand.NewSPDYExecutor(config.GetKubernetesConfig(), http.MethodPost, execRequest.URL()) + if err != nil { + fmt.Println(err.Error()) + } + + err = exec.StreamWithContext(context.Background(), streamOptions) + if err != nil { + if stderr.Len() == 0 { + panic(err) + } + outputErr := stderr.String() + return outputErr, err + } + output := stdout.String() + return output, nil +} + +func GetPodByName(podName string, podNamespace string) (*corev1.Pod, error) { + clientset, err := kubernetes.NewForConfig(config.GetKubernetesConfig()) + if err != nil { + panic(err.Error()) + } + for i := 15; i > 0; i-- { + time.Sleep(time.Second * 1) + + pod, err := clientset.CoreV1(). + Pods(podNamespace). + Get(context.Background(), podName, metav1.GetOptions{}) + if err != nil || pod.Status.Phase != "Running" { + continue + } + return pod, nil + } + return nil, err +} diff --git a/pkg/kubespray/cluster.go b/pkg/kubespray/cluster.go index 06a6dfa..06da4ec 100644 --- a/pkg/kubespray/cluster.go +++ b/pkg/kubespray/cluster.go @@ -1,7 +1,18 @@ package kubespray +import ( + "kube-forge/pkg/config" + "kube-forge/pkg/secrets_storage" +) + func InstallCluster(tags string) { runPlaybook("kubespray/project/cluster.yml", tags) + + config := config.GetConfig() + if config.Modules.SecretsStorage.Enabled { + secrets_storage.InitVault() + secrets_storage.UnsealVault() + } } func UpgradeCluster(tags string) { diff --git a/pkg/kubespray/utility.go b/pkg/kubespray/utility.go index eba9b46..ba5ff28 100644 --- a/pkg/kubespray/utility.go +++ b/pkg/kubespray/utility.go @@ -16,7 +16,7 @@ func getPlaybookParameters(tags string) playbook.AnsiblePlaybookOptions { cfg := config.GetConfig() ansiblePlaybookOptions := playbook.AnsiblePlaybookOptions{ - Inventory: filepath.Join(cfg.DataDir, "kubespray/inventory/hosts"), + Inventory: filepath.Join(cfg.WorkDir, "kubespray/inventory/hosts"), Tags: tags, User: cfg.Credentials.User, Become: true, @@ -35,7 +35,7 @@ func getPlaybookParameters(tags string) playbook.AnsiblePlaybookOptions { func CopyK8SAdminConfig(pathInDataDir string) { config := config.GetConfig() - dataDir := config.DataDir + dataDir := config.WorkDir var adminDefaultConfigPath = filepath.Join(dataDir, "kubespray/inventory/artifacts/admin.conf") var adminOutConfigPath = filepath.Join(dataDir, pathInDataDir) source, err := os.Open(adminDefaultConfigPath) diff --git a/pkg/resources/templates/helm-apps/releases/additional-modules/docker-secrets-generator.yml.tmpl b/pkg/resources/templates/helm-apps/releases/additional-modules/docker-secrets-generator.yml.tmpl index d0f78eb..23fadb2 100644 --- a/pkg/resources/templates/helm-apps/releases/additional-modules/docker-secrets-generator.yml.tmpl +++ b/pkg/resources/templates/helm-apps/releases/additional-modules/docker-secrets-generator.yml.tmpl @@ -7,8 +7,8 @@ {{- else }} release_state: "absent" {{- end }} - values: {{- if .Modules.Additional.DockerSecrets.Repositories }} + values: repositories: {{- .Modules.Additional.DockerSecrets.Repositories | toYaml | nindent 6 }} {{- end }} diff --git a/pkg/resources/templates/helm-apps/releases/secrets-storage/vault.yml.tmpl b/pkg/resources/templates/helm-apps/releases/secrets-storage/vault.yml.tmpl index fb27799..756a599 100644 --- a/pkg/resources/templates/helm-apps/releases/secrets-storage/vault.yml.tmpl +++ b/pkg/resources/templates/helm-apps/releases/secrets-storage/vault.yml.tmpl @@ -344,7 +344,7 @@ # name: http-monitoring readinessProbe: - enabled: true + enabled: false # If you need to use a http path instead of the default exec # path: /v1/sys/health?standbyok=true @@ -388,11 +388,6 @@ # Used to set the sleep time during the preStop step preStopSleepSeconds: 5 - postStart: - # - /bin/sh - # - -c - # - /vault/userconfig/myscript/run.sh - extraEnvironmentVars: {} extraSecretEnvironmentVars: [] @@ -816,6 +811,7 @@ extraLabels: {} readinessProbe: + enabled: true failureThreshold: 2 initialDelaySeconds: 5 periodSeconds: 5 diff --git a/pkg/secrets_storage/commands.go b/pkg/secrets_storage/commands.go new file mode 100644 index 0000000..0fc6b14 --- /dev/null +++ b/pkg/secrets_storage/commands.go @@ -0,0 +1,98 @@ +package secrets_storage + +import ( + "fmt" + "kube-forge/pkg/config" + "kube-forge/pkg/kubernetes_client" + "kube-forge/pkg/templates" + "regexp" + "strings" +) + +func InitVault() { + _, err := kubernetes_client.GetPodByName("vault-0", "secrets-storage") + if err != nil { + fmt.Println(err.Error()) + return + } + err = commandToInitVault() + if err != nil { + fmt.Println(err.Error()) + return + } + fmt.Println("Vault initialized") + templates.ApplyVaultInitKeysTemplate() +} + +func UnsealVault() { + _, err := kubernetes_client.GetPodByName("vault-0", "secrets-storage") + if err != nil { + fmt.Println(err.Error()) + return + } + commandToUnsealVault() +} + +// func getRunningVault(ctx context.Context, podName string, podNamespace string, responseChan chan<- error) { +// time.Sleep(1 * time.Minute) +// _, err := kubernetes_client.GetPodByName(ctx, podName, podNamespace) +// if err != nil { +// responseChan <- err +// } + +// commandToUnsealVault() +// responseChan <- nil +// close(responseChan) +// } + +func commandToInitVault() error { + config := config.GetConfig() + + command := fmt.Sprintf( + "vault operator init -key-shares=%d -key-threshold=%d", + config.Modules.SecretsStorage.KeyShares, + config.Modules.SecretsStorage.KeyThreshold, + ) + output, err := kubernetes_client.ExecuteCommandInPodContainer( + command, "secrets-storage", "vault-0", "vault", + ) + if err != nil && strings.Contains(output, "Vault is already initialized") { + return VaultAlreadyInitialised + } + + unsealKeys, rootToken := parseVaultInitKeys(output) + config.Modules.SecretsStorage.UnsealKeys = unsealKeys + config.Modules.SecretsStorage.RootToken = rootToken + return nil +} + +func parseVaultInitKeys(input string) ([]string, string) { + unsealKeyPattern := regexp.MustCompile(`Unseal Key \d+: (\S+)`) + rootTokenPattern := regexp.MustCompile(`Initial Root Token: (\S+)`) + + unsealKeysMatches := unsealKeyPattern.FindAllStringSubmatch(input, -1) + var unsealKeys []string + for _, match := range unsealKeysMatches { + unsealKeys = append(unsealKeys, match[1]) + } + + rootTokenMatches := rootTokenPattern.FindStringSubmatch(input) + rootToken := rootTokenMatches[1] + + return unsealKeys, rootToken +} + +func commandToUnsealVault() { + config := config.GetConfig() + + for _, unsealKey := range config.Modules.SecretsStorage.UnsealKeys { + command := fmt.Sprintf( + "vault operator unseal %s", + unsealKey, + ) + kubernetes_client.ExecuteCommandInPodContainer( + command, "secrets-storage", "vault-0", "vault", + ) + } + fmt.Println("Vault unsealed") +} diff --git a/pkg/secrets_storage/errors.go b/pkg/secrets_storage/errors.go new file mode 100644 index 0000000..4a92e37 --- /dev/null +++ b/pkg/secrets_storage/errors.go @@ -0,0 +1,5 @@ +package secrets_storage + +import "errors" + +var VaultAlreadyInitialised = errors.New("Vault already initialised") diff --git a/pkg/templates/templates.go b/pkg/templates/helm_apps.go similarity index 56% rename from pkg/templates/templates.go rename to pkg/templates/helm_apps.go index c1b699d..f142002 100644 --- a/pkg/templates/templates.go +++ b/pkg/templates/helm_apps.go @@ -1,23 +1,11 @@ package templates import ( - "bytes" - "embed" "kube-forge/pkg/config" "kube-forge/pkg/resources" - "os" - "path/filepath" "strings" - "text/template" ) -var K8S_TEMPLATES = [...][2]string{ - {"templates/kubespray/inventory/hosts.tmpl", "kubespray/inventory/hosts"}, - {"templates/kubespray/inventory/group_vars/all.yml.tmpl", "kubespray/inventory/group_vars/all.yml"}, - {"templates/kubespray/inventory/group_vars/k8s_cluster/addons.yml.tmpl", "kubespray/inventory/group_vars/k8s_cluster/addons.yml"}, - {"templates/kubespray/inventory/group_vars/k8s_cluster/k8s-cluster.yml.tmpl", "kubespray/inventory/group_vars/k8s_cluster/k8s-cluster.yml"}, -} - var HELM_APPS_TEMPLATES = [...]string{ "templates/helm-apps/releases/additional-modules/docker-secrets-generator.yml.tmpl", "templates/helm-apps/releases/additional-modules/longhorn.yml.tmpl", @@ -41,49 +29,6 @@ var HELM_REPOSITORIES_TEMPLATES = [...]string{ "templates/helm-apps/repositories/repositories.yml.tmpl", } -func executeTemplateToString(template *template.Template, config *config.Config) string { - templateResult := &bytes.Buffer{} - err := template.Execute(templateResult, config) - if err != nil { - panic(err) - } - templateResultString := templateResult.String() - return templateResultString -} - -func getTemplateFromEmbedFSFolder(embedFS embed.FS, templateFile string) *template.Template { - templateData, err := embedFS.ReadFile(templateFile) - if err != nil { - panic(err) - } - templateDataString := string(templateData) - template, err := template.New("tmpl").Funcs(funcMap()).Parse(templateDataString) - if err != nil { - panic(err) - } - return template -} - -func applyTemplates() { - config := config.GetConfig() - for _, templateData := range K8S_TEMPLATES { - var templateFile = templateData[0] - var outFile = filepath.Join(config.DataDir, templateData[1]) - - tmpl := getTemplateFromEmbedFSFolder(resources.Templates, templateFile) - - file, err := os.Create(outFile) - if err != nil { - panic(err) - } - defer file.Close() - err = tmpl.Execute(file, config) - if err != nil { - panic(err) - } - } -} - func GetHelmAppsConfigData() (string, string) { cfg := config.GetConfig() helmAppsTemplateResults := []string{} @@ -98,7 +43,3 @@ func GetHelmAppsConfigData() (string, string) { } return strings.Join(repositoriesTemplateResults, "\n"), strings.Join(helmAppsTemplateResults, "\n") } - -func ApplyTemplates() { - applyTemplates() -} diff --git a/pkg/templates/kubespray.go b/pkg/templates/kubespray.go new file mode 100644 index 0000000..13e9822 --- /dev/null +++ b/pkg/templates/kubespray.go @@ -0,0 +1,12 @@ +package templates + +var K8S_TEMPLATES = [...][2]string{ + {"templates/kubespray/inventory/hosts.tmpl", "kubespray/inventory/hosts"}, + {"templates/kubespray/inventory/group_vars/all.yml.tmpl", "kubespray/inventory/group_vars/all.yml"}, + {"templates/kubespray/inventory/group_vars/k8s_cluster/addons.yml.tmpl", "kubespray/inventory/group_vars/k8s_cluster/addons.yml"}, + {"templates/kubespray/inventory/group_vars/k8s_cluster/k8s-cluster.yml.tmpl", "kubespray/inventory/group_vars/k8s_cluster/k8s-cluster.yml"}, +} + +func ApplyK8sTemplates() { + applyTemplates(K8S_TEMPLATES[:]) +} diff --git a/pkg/templates/secrets_storage.go b/pkg/templates/secrets_storage.go new file mode 100644 index 0000000..a972d40 --- /dev/null +++ b/pkg/templates/secrets_storage.go @@ -0,0 +1,14 @@ +package templates + +import ( + "fmt" + "kube-forge/pkg/config" +) + +func ApplyVaultInitKeysTemplate() { + config := config.GetConfig() + var VAULT_INIT_KEYS_TEMPLATE = [...][2]string{ + {"templates/secrets-storage/vault-keys.json.tmpl", fmt.Sprintf("%s/vault-keys.json", config.WorkDir)}, + } + applyTemplates(VAULT_INIT_KEYS_TEMPLATE[:]) +} diff --git a/pkg/templates/utility.go b/pkg/templates/utility.go new file mode 100644 index 0000000..e40e713 --- /dev/null +++ b/pkg/templates/utility.go @@ -0,0 +1,54 @@ +package templates + +import ( + "bytes" + "embed" + "kube-forge/pkg/config" + "kube-forge/pkg/resources" + "os" + "path/filepath" + "text/template" +) + +func executeTemplateToString(template *template.Template, config *config.Config) string { + templateResult := &bytes.Buffer{} + err := template.Execute(templateResult, config) + if err != nil { + panic(err) + } + templateResultString := templateResult.String() + return templateResultString +} + +func getTemplateFromEmbedFSFolder(embedFS embed.FS, templateFile string) *template.Template { + templateData, err := embedFS.ReadFile(templateFile) + if err != nil { + panic(err) + } + templateDataString := string(templateData) + template, err := template.New("tmpl").Funcs(funcMap()).Parse(templateDataString) + if err != nil { + panic(err) + } + return template +} + +func applyTemplates(templates [][2]string) { + config := config.GetConfig() + for _, templateData := range templates { + var templateFile = templateData[0] + var outFile = filepath.Join(config.WorkDir, templateData[1]) + + tmpl := getTemplateFromEmbedFSFolder(resources.Templates, templateFile) + + file, err := os.Create(outFile) + if err != nil { + panic(err) + } + defer file.Close() + err = tmpl.Execute(file, config) + if err != nil { + panic(err) + } + } +}