Auto import kubernetes template in Helm charts (#3550)

This commit is contained in:
Dean Sheather
2022-08-26 05:32:35 +10:00
committed by GitHub
parent 94e96fa40b
commit 14a9576b77
15 changed files with 423 additions and 41 deletions
@@ -1,14 +1,16 @@
---
name: Develop multiple services in Kubernetes
name: Develop in Kubernetes
description: Get started with Kubernetes development.
tags: [cloud, kubernetes]
---
# Getting started
This template creates a pod running the `codercom/enterprise-base:ubuntu` image.
## RBAC
The Coder provisioner requires permission to administer pods to use this template. The template
The Coder provisioner requires permission to administer pods to use this template. The template
creates workspaces in a single Kubernetes namespace, using the `workspaces_namespace` parameter set
while creating the template.
@@ -20,15 +22,15 @@ kind: Role
metadata:
name: coder
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["*"]
- apiGroups: [""]
resources: ["pods"]
verbs: ["*"]
```
## Authentication
This template can authenticate using in-cluster authentication, or using a kubeconfig local to the
Coder host. For additional authentication options, consult the [Kubernetes provider
Coder host. For additional authentication options, consult the [Kubernetes provider
documentation](https://registry.terraform.io/providers/hashicorp/kubernetes/latest/docs).
### kubeconfig on Coder host
@@ -46,8 +48,8 @@ you can use in-cluster authentication.
To use this authentication, set the parameter `use_kubeconfig` to false.
The Terraform provisioner will automatically use the service account associated with the pod to
authenticate to Kubernetes. Be sure to bind a [role with appropriate permission](#rbac) to the
service account. For example, assuming the Coder host runs in the same namespace as you intend
authenticate to Kubernetes. Be sure to bind a [role with appropriate permission](#rbac) to the
service account. For example, assuming the Coder host runs in the same namespace as you intend
to create workspaces:
```yaml
@@ -25,17 +25,21 @@ variable "use_kubeconfig" {
EOF
}
variable "coder_namespace" {
variable "namespace" {
type = string
sensitive = true
description = "The namespace to create workspaces in (must exist prior to creating workspaces)"
default = "coder-namespace"
default = "coder-workspaces"
}
variable "disk_size" {
type = number
description = "Disk size (__ GB)"
variable "home_disk_size" {
type = number
description = "How large would you like your home volume to be (in GB)?"
default = 10
validation {
condition = var.home_disk_size >= 1
error_message = "Value must be greater than or equal to 1."
}
}
provider "kubernetes" {
@@ -46,8 +50,8 @@ provider "kubernetes" {
data "coder_workspace" "me" {}
resource "coder_agent" "main" {
os = "linux"
arch = "amd64"
os = "linux"
arch = "amd64"
startup_script = <<EOT
#!/bin/bash
@@ -66,11 +70,26 @@ resource "coder_app" "code-server" {
relative_path = true
}
resource "kubernetes_persistent_volume_claim" "home" {
metadata {
name = "coder-${data.coder_workspace.me.owner}-${data.coder_workspace.me.name}-home"
namespace = var.namespace
}
spec {
access_modes = ["ReadWriteOnce"]
resources {
requests = {
storage = "${var.home_disk_size}Gi"
}
}
}
}
resource "kubernetes_pod" "main" {
count = data.coder_workspace.me.start_count
metadata {
name = "coder-${data.coder_workspace.me.owner}-${data.coder_workspace.me.name}"
namespace = var.coder_namespace
namespace = var.namespace
}
spec {
security_context {
@@ -90,28 +109,16 @@ resource "kubernetes_pod" "main" {
}
volume_mount {
mount_path = "/home/coder"
name = "home-directory"
name = "home"
read_only = false
}
}
volume {
name = "home-directory"
persistent_volume_claim {
claim_name = kubernetes_persistent_volume_claim.home-directory.metadata.0.name
}
}
}
}
resource "kubernetes_persistent_volume_claim" "home-directory" {
metadata {
name = "home-coder-java-${data.coder_workspace.me.owner}-${data.coder_workspace.me.name}"
namespace = var.coder_namespace
}
spec {
access_modes = ["ReadWriteOnce"]
resources {
requests = {
storage = "${var.disk_size}Gi"
volume {
name = "home"
persistent_volume_claim {
claim_name = kubernetes_persistent_volume_claim.home.metadata.0.name
read_only = false
}
}
}