mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add external provisioner daemon helm chart (#8939)
* Refactor helm to extract common templates to libcoder Signed-off-by: Spike Curtis <spike@coder.com> * Remove comment from libcoder Chart.yaml Signed-off-by: Spike Curtis <spike@coder.com> * Add provisioner helm chart * Fix prettier, linting, docs Signed-off-by: Spike Curtis <spike@coder.com> * Log at INFO when provisionerd connects to coderd Signed-off-by: Spike Curtis <spike@coder.com> * remove unnecessary exports in helm tests Signed-off-by: Spike Curtis <spike@coder.com> --------- Signed-off-by: Spike Curtis <spike@coder.com>
This commit is contained in:
@@ -0,0 +1,13 @@
|
||||
apiVersion: v2
|
||||
name: libcoder
|
||||
description: Coder library chart
|
||||
home: https://github.com/coder/coder
|
||||
|
||||
type: library
|
||||
version: "0.1.0"
|
||||
appVersion: "0.1.0"
|
||||
|
||||
maintainers:
|
||||
- name: Coder Technologies, Inc.
|
||||
email: support@coder.com
|
||||
url: https://coder.com/contact
|
||||
@@ -0,0 +1,85 @@
|
||||
{{- define "libcoder.deployment.tpl" -}}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "coder.name" .}}
|
||||
labels:
|
||||
{{- include "coder.labels" . | nindent 4 }}
|
||||
{{- with .Values.coder.labels }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
annotations: {{ toYaml .Values.coder.annotations | nindent 4}}
|
||||
spec:
|
||||
replicas: {{ .Values.coder.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "coder.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "coder.labels" . | nindent 8 }}
|
||||
{{- with .Values.coder.podLabels }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
annotations:
|
||||
{{- toYaml .Values.coder.podAnnotations | nindent 8 }}
|
||||
spec:
|
||||
serviceAccountName: {{ .Values.coder.serviceAccount.name | quote }}
|
||||
restartPolicy: Always
|
||||
{{- with .Values.coder.image.pullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
terminationGracePeriodSeconds: 60
|
||||
{{- with .Values.coder.affinity }}
|
||||
affinity:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.coder.tolerations }}
|
||||
tolerations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.coder.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.coder.initContainers }}
|
||||
initContainers:
|
||||
{{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers: []
|
||||
{{- include "coder.volumes" . | nindent 6 }}
|
||||
{{- end -}}
|
||||
{{- define "libcoder.deployment" -}}
|
||||
{{- include "libcoder.util.merge" (append . "libcoder.deployment.tpl") -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "libcoder.containerspec.tpl" -}}
|
||||
name: coder
|
||||
image: {{ include "coder.image" . | quote }}
|
||||
imagePullPolicy: {{ .Values.coder.image.pullPolicy }}
|
||||
command:
|
||||
{{- toYaml .Values.coder.command | nindent 2 }}
|
||||
resources:
|
||||
{{- toYaml .Values.coder.resources | nindent 2 }}
|
||||
lifecycle:
|
||||
{{- toYaml .Values.coder.lifecycle | nindent 2 }}
|
||||
securityContext: {{ toYaml .Values.coder.securityContext | nindent 2 }}
|
||||
{{ include "coder.volumeMounts" . }}
|
||||
{{- end -}}
|
||||
{{- define "libcoder.containerspec" -}}
|
||||
{{- include "libcoder.util.merge" (append . "libcoder.containerspec.tpl") -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "libcoder.serviceaccount.tpl" -}}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ .Values.coder.serviceAccount.name | quote }}
|
||||
annotations: {{ toYaml .Values.coder.serviceAccount.annotations | nindent 4 }}
|
||||
labels:
|
||||
{{- include "coder.labels" . | nindent 4 }}
|
||||
{{- end -}}
|
||||
{{- define "libcoder.serviceaccount" -}}
|
||||
{{- include "libcoder.util.merge" (append . "libcoder.serviceaccount.tpl") -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,200 @@
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "coder.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create chart name and version as used by the chart label.
|
||||
*/}}
|
||||
{{- define "coder.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Selector labels
|
||||
|
||||
!!!!! DO NOT ADD ANY MORE SELECTORS. IT IS A BREAKING CHANGE !!!!!
|
||||
*/}}
|
||||
{{- define "coder.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "coder.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "coder.labels" -}}
|
||||
helm.sh/chart: {{ include "coder.chart" . }}
|
||||
{{ include "coder.selectorLabels" . }}
|
||||
app.kubernetes.io/part-of: {{ include "coder.name" . }}
|
||||
{{- if .Chart.AppVersion }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
{{- end }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder Docker image URI
|
||||
*/}}
|
||||
{{- define "coder.image" -}}
|
||||
{{- if and (eq .Values.coder.image.tag "") (eq .Chart.AppVersion "0.1.0") -}}
|
||||
{{ fail "You must specify the coder.image.tag value if you're installing the Helm chart directly from Git." }}
|
||||
{{- end -}}
|
||||
{{ .Values.coder.image.repo }}:{{ .Values.coder.image.tag | default (printf "v%v" .Chart.AppVersion) }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder TLS enabled.
|
||||
*/}}
|
||||
{{- define "coder.tlsEnabled" -}}
|
||||
{{- if hasKey .Values.coder "tls" -}}
|
||||
{{- if .Values.coder.tls.secretNames -}}
|
||||
true
|
||||
{{- else -}}
|
||||
false
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
false
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder TLS environment variables.
|
||||
*/}}
|
||||
{{- define "coder.tlsEnv" }}
|
||||
{{- if eq (include "coder.tlsEnabled" .) "true" }}
|
||||
- name: CODER_TLS_ENABLE
|
||||
value: "true"
|
||||
- name: CODER_TLS_ADDRESS
|
||||
value: "0.0.0.0:8443"
|
||||
- name: CODER_TLS_CERT_FILE
|
||||
value: "{{ range $idx, $secretName := .Values.coder.tls.secretNames -}}{{ if $idx }},{{ end }}/etc/ssl/certs/coder/{{ $secretName }}/tls.crt{{- end }}"
|
||||
- name: CODER_TLS_KEY_FILE
|
||||
value: "{{ range $idx, $secretName := .Values.coder.tls.secretNames -}}{{ if $idx }},{{ end }}/etc/ssl/certs/coder/{{ $secretName }}/tls.key{{- end }}"
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder default access URL
|
||||
*/}}
|
||||
{{- define "coder.defaultAccessURL" }}
|
||||
{{- if eq (include "coder.tlsEnabled" .) "true" -}}
|
||||
https
|
||||
{{- else -}}
|
||||
http
|
||||
{{- end -}}
|
||||
://coder.{{ .Release.Namespace }}.svc.cluster.local
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder volume definitions.
|
||||
*/}}
|
||||
{{- define "coder.volumeList" }}
|
||||
{{- if hasKey .Values.coder "tls" -}}
|
||||
{{- range $secretName := .Values.coder.tls.secretNames }}
|
||||
- name: "tls-{{ $secretName }}"
|
||||
secret:
|
||||
secretName: {{ $secretName | quote }}
|
||||
{{ end -}}
|
||||
{{- end }}
|
||||
{{ range $secret := .Values.coder.certs.secrets -}}
|
||||
- name: "ca-cert-{{ $secret.name }}"
|
||||
secret:
|
||||
secretName: {{ $secret.name | quote }}
|
||||
{{ end -}}
|
||||
{{ if gt (len .Values.coder.volumes) 0 -}}
|
||||
{{ toYaml .Values.coder.volumes }}
|
||||
{{ end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder volumes yaml.
|
||||
*/}}
|
||||
{{- define "coder.volumes" }}
|
||||
{{- if trim (include "coder.volumeList" .) -}}
|
||||
volumes:
|
||||
{{- include "coder.volumeList" . -}}
|
||||
{{- else -}}
|
||||
volumes: []
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder volume mounts.
|
||||
*/}}
|
||||
{{- define "coder.volumeMountList" }}
|
||||
{{- if hasKey .Values.coder "tls" }}
|
||||
{{ range $secretName := .Values.coder.tls.secretNames -}}
|
||||
- name: "tls-{{ $secretName }}"
|
||||
mountPath: "/etc/ssl/certs/coder/{{ $secretName }}"
|
||||
readOnly: true
|
||||
{{ end -}}
|
||||
{{- end }}
|
||||
{{ range $secret := .Values.coder.certs.secrets -}}
|
||||
- name: "ca-cert-{{ $secret.name }}"
|
||||
mountPath: "/etc/ssl/certs/{{ $secret.name }}.crt"
|
||||
subPath: {{ $secret.key | quote }}
|
||||
readOnly: true
|
||||
{{ end -}}
|
||||
{{ if gt (len .Values.coder.volumeMounts) 0 -}}
|
||||
{{ toYaml .Values.coder.volumeMounts }}
|
||||
{{ end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder volume mounts yaml.
|
||||
*/}}
|
||||
{{- define "coder.volumeMounts" }}
|
||||
{{- if trim (include "coder.volumeMountList" .) -}}
|
||||
volumeMounts:
|
||||
{{- include "coder.volumeMountList" . -}}
|
||||
{{- else -}}
|
||||
volumeMounts: []
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Coder ingress wildcard hostname with the wildcard suffix stripped.
|
||||
*/}}
|
||||
{{- define "coder.ingressWildcardHost" -}}
|
||||
{{/* This regex replace is required as the original input including the suffix
|
||||
* is not a legal ingress host. We need to remove the suffix and keep the
|
||||
* wildcard '*'.
|
||||
*
|
||||
* - '\\*' Starts with '*'
|
||||
* - '[^.]*' Suffix is 0 or more characters, '-suffix'
|
||||
* - '(' Start domain capture group
|
||||
* - '\\.' The domain should be separated with a '.' from the subdomain
|
||||
* - '.*' Rest of the domain.
|
||||
* - ')' $1 is the ''.example.com'
|
||||
*/}}
|
||||
{{- regexReplaceAll "\\*[^.]*(\\..*)" .Values.coder.ingress.wildcardHost "*${1}" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Fail on fully deprecated values or deprecated value combinations. This is
|
||||
included at the top of coder.yaml.
|
||||
*/}}
|
||||
{{- define "coder.verifyDeprecated" }}
|
||||
{{/*
|
||||
Deprecated value coder.tls.secretName must not be used.
|
||||
*/}}
|
||||
{{- if .Values.coder.tls.secretName }}
|
||||
{{ fail "coder.tls.secretName is deprecated, use coder.tls.secretNames instead." }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Renders a value that contains a template.
|
||||
Usage:
|
||||
{{ include "coder.renderTemplate" ( dict "value" .Values.path.to.the.Value "context" $) }}
|
||||
*/}}
|
||||
{{- define "coder.renderTemplate" -}}
|
||||
{{- if typeIs "string" .value }}
|
||||
{{- tpl .value .context }}
|
||||
{{- else }}
|
||||
{{- tpl (.value | toYaml) .context }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,59 @@
|
||||
{{- define "libcoder.rbac.tpl" -}}
|
||||
{{- if .Values.coder.serviceAccount.workspacePerms }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ .Values.coder.serviceAccount.name }}-workspace-perms
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["pods"]
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- deletecollection
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups: [""]
|
||||
resources: ["persistentvolumeclaims"]
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- deletecollection
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
{{- if .Values.coder.serviceAccount.enableDeployments }}
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- deletecollection
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ .Values.coder.serviceAccount.name | quote }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ .Values.coder.serviceAccount.name | quote }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ .Values.coder.serviceAccount.name }}-workspace-perms
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,13 @@
|
||||
{{- /*
|
||||
libcoder.util.merge will merge two YAML templates and output the result.
|
||||
This takes an array of three values:
|
||||
- the top context
|
||||
- the template name of the overrides (destination)
|
||||
- the template name of the base (source)
|
||||
*/}}
|
||||
{{- define "libcoder.util.merge" -}}
|
||||
{{- $top := first . -}}
|
||||
{{- $overrides := fromYaml (include (index . 1) $top) | default (dict ) -}}
|
||||
{{- $tpl := fromYaml (include (index . 2) $top) | default (dict ) -}}
|
||||
{{- toYaml (merge $overrides $tpl) -}}
|
||||
{{- end -}}
|
||||
Reference in New Issue
Block a user