Ingres-nginx upgrade

This PS bumps up ingress-nginx version to 1.11.2 due to critical CVE

Also we bump up helm to 3.15.4

Change-Id: Id8e40bbbd10fb5aa525cc666f938f3803823ea48
This commit is contained in:
Sergiy Markin 2024-08-23 23:40:52 +00:00
parent c831a4c658
commit 01d4c1b751
10 changed files with 34 additions and 24 deletions

View File

@ -175,7 +175,7 @@
voting: true voting: true
vars: vars:
site: airskiff site: airskiff
HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.13.2-linux-amd64.tar.gz HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.15.4-linux-amd64.tar.gz
HTK_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8 HTK_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8
OSH_INFRA_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8 OSH_INFRA_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8
OSH_COMMIT: 049e679939fbd3b0c659dd0977911b8dc3b5a015 OSH_COMMIT: 049e679939fbd3b0c659dd0977911b8dc3b5a015
@ -192,6 +192,7 @@
- ./tools/deployment/airskiff/developer/100-deploy-osh.sh - ./tools/deployment/airskiff/developer/100-deploy-osh.sh
- ./tools/deployment/airskiff/common/os-env.sh - ./tools/deployment/airskiff/common/os-env.sh
- ./tools/gate/wait-for-shipyard.sh - ./tools/gate/wait-for-shipyard.sh
# - ./tools/deployment/airskiff/common/sleep.sh
- job: - job:
name: treasuremap-airskiff-1node-reduced-site name: treasuremap-airskiff-1node-reduced-site
@ -203,7 +204,7 @@
voting: true voting: true
vars: vars:
site: airskiff site: airskiff
HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.13.2-linux-amd64.tar.gz HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.15.4-linux-amd64.tar.gz
HTK_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8 HTK_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8
OSH_INFRA_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8 OSH_INFRA_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8
OSH_COMMIT: 049e679939fbd3b0c659dd0977911b8dc3b5a015 OSH_COMMIT: 049e679939fbd3b0c659dd0977911b8dc3b5a015
@ -218,6 +219,7 @@
- ./tools/deployment/airskiff/developer/017-make-all-images.sh - ./tools/deployment/airskiff/developer/017-make-all-images.sh
- ./tools/deployment/airskiff/developer/025-start-artifactory.sh - ./tools/deployment/airskiff/developer/025-start-artifactory.sh
- ./tools/deployment/airskiff/developer/026-reduce-site.sh - ./tools/deployment/airskiff/developer/026-reduce-site.sh
- ./tools/deployment/airskiff/developer/020-setup-client.sh
- ./tools/deployment/airskiff/developer/030-armada-bootstrap.sh - ./tools/deployment/airskiff/developer/030-armada-bootstrap.sh
- ./tools/deployment/airskiff/developer/100-deploy-osh.sh - ./tools/deployment/airskiff/developer/100-deploy-osh.sh
- ./tools/deployment/airskiff/common/os-env.sh - ./tools/deployment/airskiff/common/os-env.sh
@ -234,7 +236,7 @@
voting: true voting: true
vars: vars:
site: airskiff site: airskiff
HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.13.2-linux-amd64.tar.gz HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.15.4-linux-amd64.tar.gz
HTK_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8 HTK_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8
OSH_INFRA_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8 OSH_INFRA_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8
OSH_COMMIT: 049e679939fbd3b0c659dd0977911b8dc3b5a015 OSH_COMMIT: 049e679939fbd3b0c659dd0977911b8dc3b5a015
@ -382,7 +384,7 @@
post-run: tools/gate/playbooks/debug-report.yaml post-run: tools/gate/playbooks/debug-report.yaml
vars: vars:
site: airskiff site: airskiff
HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.13.2-linux-amd64.tar.gz HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.15.4-linux-amd64.tar.gz
HTK_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8 HTK_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8
OSH_INFRA_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8 OSH_INFRA_COMMIT: 05f2f45971abcf483189358d663e2b46c3fc2fe8
OSH_COMMIT: 049e679939fbd3b0c659dd0977911b8dc3b5a015 OSH_COMMIT: 049e679939fbd3b0c659dd0977911b8dc3b5a015

View File

@ -32,7 +32,7 @@ data:
subpath: haproxy subpath: haproxy
type: tar type: tar
ingress: ingress:
location: https://github.com/kubernetes/ingress-nginx/releases/download/helm-chart-4.8.3/ingress-nginx-4.8.3.tgz location: https://github.com/kubernetes/ingress-nginx/releases/download/helm-chart-4.11.2/ingress-nginx-4.11.2.tgz
subpath: ingress-nginx subpath: ingress-nginx
type: tar type: tar
proxy: proxy:
@ -75,7 +75,7 @@ data:
subpath: helm-toolkit subpath: helm-toolkit
type: git type: git
ingress: ingress:
location: https://github.com/kubernetes/ingress-nginx/releases/download/helm-chart-4.8.3/ingress-nginx-4.8.3.tgz location: https://github.com/kubernetes/ingress-nginx/releases/download/helm-chart-4.11.2/ingress-nginx-4.11.2.tgz
subpath: ingress-nginx subpath: ingress-nginx
type: tar type: tar
keystone: keystone:
@ -267,7 +267,7 @@ data:
subpath: drydock subpath: drydock
type: tar type: tar
ingress: ingress:
location: https://github.com/kubernetes/ingress-nginx/releases/download/helm-chart-4.8.3/ingress-nginx-4.8.3.tgz location: https://github.com/kubernetes/ingress-nginx/releases/download/helm-chart-4.11.2/ingress-nginx-4.11.2.tgz
subpath: ingress-nginx subpath: ingress-nginx
type: tar type: tar
keystone: keystone:
@ -488,7 +488,7 @@ data:
anchor: gcr.io/google-containers/hyperkube-amd64:v1.17.3 anchor: gcr.io/google-containers/hyperkube-amd64:v1.17.3
controller_manager: gcr.io/google-containers/hyperkube-amd64:v1.17.3 controller_manager: gcr.io/google-containers/hyperkube-amd64:v1.17.3
coredns: coredns:
coredns: coredns/coredns:1.9.4 coredns: coredns/coredns:1.11.1
test: quay.io/airshipit/promenade:latest test: quay.io/airshipit/promenade:latest
etcd: etcd:
etcd: quay.io/coreos/etcd:v3.5.11 etcd: quay.io/coreos/etcd:v3.5.11
@ -499,9 +499,9 @@ data:
test: docker.io/library/python:3.6 test: docker.io/library/python:3.6
hyperkube: gcr.io/google-containers/hyperkube-amd64:v1.17.3 hyperkube: gcr.io/google-containers/hyperkube-amd64:v1.17.3
ingress: ingress:
controller: registry.k8s.io/ingress-nginx/controller:v1.9.4 controller: registry.k8s.io/ingress-nginx/controller:v1.11.2
defaultBackend: k8s.gcr.io/defaultbackend-amd64:1.5 defaultBackend: k8s.gcr.io/defaultbackend-amd64:1.5
patch: k8s.gcr.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c343 patch: k8s.gcr.io/ingress-nginx/kube-webhook-certgen:v1.4.3
pause: gcr.io/google-containers/pause-amd64:3.1 pause: gcr.io/google-containers/pause-amd64:3.1
proxy: proxy:
proxy: gcr.io/google-containers/hyperkube-amd64:v1.17.3 proxy: gcr.io/google-containers/hyperkube-amd64:v1.17.3
@ -584,9 +584,9 @@ data:
horizon_db_sync: docker.io/openstackhelm/horizon:ocata-ubuntu_xenial-20200513 horizon_db_sync: docker.io/openstackhelm/horizon:ocata-ubuntu_xenial-20200513
test: docker.io/openstackhelm/osh-selenium:latest-ubuntu_bionic test: docker.io/openstackhelm/osh-selenium:latest-ubuntu_bionic
ingress: ingress:
controller: registry.k8s.io/ingress-nginx/controller:v1.9.4 controller: registry.k8s.io/ingress-nginx/controller:v1.11.2
defaultBackend: k8s.gcr.io/defaultbackend-amd64:1.5 defaultBackend: k8s.gcr.io/defaultbackend-amd64:1.5
patch: k8s.gcr.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c343 patch: k8s.gcr.io/ingress-nginx/kube-webhook-certgen:v1.4.3
keystone: keystone:
bootstrap: docker.io/openstackhelm/heat:wallaby-ubuntu_focal bootstrap: docker.io/openstackhelm/heat:wallaby-ubuntu_focal
test: docker.io/xrally/xrally-openstack:2.0.0 test: docker.io/xrally/xrally-openstack:2.0.0
@ -822,7 +822,7 @@ data:
drydock_db_cleanup: quay.io/airshipit/drydock:master drydock_db_cleanup: quay.io/airshipit/drydock:master
drydock_db_sync: quay.io/airshipit/drydock:master drydock_db_sync: quay.io/airshipit/drydock:master
ingress: ingress:
controller: registry.k8s.io/ingress-nginx/controller:v1.9.4 controller: registry.k8s.io/ingress-nginx/controller:v1.11.2
defaultBackend: k8s.gcr.io/defaultbackend-amd64:1.5 defaultBackend: k8s.gcr.io/defaultbackend-amd64:1.5
patch: k8s.gcr.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c343 patch: k8s.gcr.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c343
keystone: keystone:
@ -857,8 +857,8 @@ data:
maas_syslog: quay.io/airshipit/maas-region-controller:latest maas_syslog: quay.io/airshipit/maas-region-controller:latest
mariadb: mariadb:
mariadb: docker.io/openstackhelm/mariadb:latest-ubuntu_focal mariadb: docker.io/openstackhelm/mariadb:latest-ubuntu_focal
ingress: registry.k8s.io/ingress-nginx/controller:v1.5.1 ingress: registry.k8s.io/ingress-nginx/controller:v1.11.2
error_pages: registry.k8s.io/defaultbackend:1.4 error_pages: k8s.gcr.io/defaultbackend-amd64:1.5
prometheus_create_mysql_user: docker.io/library/mariadb:10.6.14-focal prometheus_create_mysql_user: docker.io/library/mariadb:10.6.14-focal
prometheus_mysql_exporter: docker.io/prom/mysqld-exporter:v0.12.1 prometheus_mysql_exporter: docker.io/prom/mysqld-exporter:v0.12.1
prometheus_mysql_exporter_helm_tests: docker.io/openstackhelm/heat:wallaby-ubuntu_focal prometheus_mysql_exporter_helm_tests: docker.io/openstackhelm/heat:wallaby-ubuntu_focal

View File

@ -18,8 +18,8 @@
set -xe set -xe
: "${INSTALL_PATH:="../"}" : "${INSTALL_PATH:="../"}"
: "${OSH_COMMIT:="176b412072969f982386db9560b6f50fcb7e0148"}" : "${OSH_COMMIT:="049e679939fbd3b0c659dd0977911b8dc3b5a015"}"
: "${OSH_INFRA_COMMIT:="6ca83be78013446540b68fd28d0a75d5b2329f40"}" : "${OSH_INFRA_COMMIT:="05f2f45971abcf483189358d663e2b46c3fc2fe8"}"
: "${CLONE_ARMADA:=true}" : "${CLONE_ARMADA:=true}"
: "${CLONE_ARMADA_GO:=true}" : "${CLONE_ARMADA_GO:=true}"
: "${CLONE_ARMADA_OPERATOR:=true}" : "${CLONE_ARMADA_OPERATOR:=true}"
@ -87,14 +87,14 @@ if [[ ${CLONE_PORTHOLE} = true ]] ; then
git clone "https://review.opendev.org/airship/porthole.git" git clone "https://review.opendev.org/airship/porthole.git"
fi fi
if [[ ${CLONE_OSH} = true ]] ; then if [[ ${CLONE_OSH} = true ]] ; then
git clone https://opendev.org/openstack/openstack-helm.git git clone "https://opendev.org/openstack/openstack-helm.git"
pushd openstack-helm pushd openstack-helm
git checkout "${OSH_COMMIT}" git checkout "${OSH_COMMIT}"
popd popd
fi fi
git clone https://opendev.org/openstack/openstack-helm-infra.git git clone "https://opendev.org/openstack/openstack-helm-infra.git"
pushd openstack-helm-infra pushd openstack-helm-infra
git checkout "${OSH_INFRA_COMMIT}" git checkout "${OSH_INFRA_COMMIT}"
popd popd

View File

@ -0,0 +1,7 @@
#!/bin/bash
set -ex
while true; do
echo "Sleeping for 100 seconds..."
done

View File

@ -25,7 +25,7 @@ if [ -n "${PROXY}" ]; then
fi fi
# Deploy K8s with Minikube # Deploy K8s with Minikube
: "${HELM_VERSION:="v3.13.2"}" : "${HELM_VERSION:="v3.15.4"}"
: "${KUBE_VERSION:="v1.29.2"}" : "${KUBE_VERSION:="v1.29.2"}"
: "${MINIKUBE_VERSION:="v1.30.1"}" : "${MINIKUBE_VERSION:="v1.30.1"}"
: "${CRICTL_VERSION:="v1.29.0"}" : "${CRICTL_VERSION:="v1.29.0"}"

View File

@ -14,4 +14,5 @@
- hosts: all - hosts: all
roles: roles:
- start-zuul-console - start-zuul-console
... ...

View File

@ -19,7 +19,7 @@ osh_params:
container_distro_version: focal container_distro_version: focal
# feature_gates: # feature_gates:
site: airskiff site: airskiff
HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.13.2-linux-amd64.tar.gz HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.15.4-linux-amd64.tar.gz
HTK_COMMIT: 6ca83be78013446540b68fd28d0a75d5b2329f40 HTK_COMMIT: 6ca83be78013446540b68fd28d0a75d5b2329f40
OSH_INFRA_COMMIT: 6ca83be78013446540b68fd28d0a75d5b2329f40 OSH_INFRA_COMMIT: 6ca83be78013446540b68fd28d0a75d5b2329f40
OSH_COMMIT: 176b412072969f982386db9560b6f50fcb7e0148 OSH_COMMIT: 176b412072969f982386db9560b6f50fcb7e0148

View File

@ -35,7 +35,7 @@
FEATURE_GATES: "{{ osh_params.feature_gates | default('') }}" FEATURE_GATES: "{{ osh_params.feature_gates | default('') }}"
RUN_HELM_TESTS: "{{ run_helm_tests | default('yes') }}" RUN_HELM_TESTS: "{{ run_helm_tests | default('yes') }}"
PL_SITE: "{{ site | default('airskiff') }}" PL_SITE: "{{ site | default('airskiff') }}"
HELM_ARTIFACT_URL: "{{ HELM_ARTIFACT_URL | default('https://get.helm.sh/helm-v3.13.2-linux-amd64.tar.gz') }}" HELM_ARTIFACT_URL: "{{ HELM_ARTIFACT_URL | default('https://get.helm.sh/helm-v3.15.4-linux-amd64.tar.gz') }}"
HTK_COMMIT: "{{ HTK_COMMIT | default('6ca83be78013446540b68fd28d0a75d5b2329f40') }}" HTK_COMMIT: "{{ HTK_COMMIT | default('6ca83be78013446540b68fd28d0a75d5b2329f40') }}"
OSH_INFRA_COMMIT: "{{ OSH_INFRA_COMMIT | default('6ca83be78013446540b68fd28d0a75d5b2329f40') }}" OSH_INFRA_COMMIT: "{{ OSH_INFRA_COMMIT | default('6ca83be78013446540b68fd28d0a75d5b2329f40') }}"
OSH_COMMIT: "{{ OSH_COMMIT | default('176b412072969f982386db9560b6f50fcb7e0148') }}" OSH_COMMIT: "{{ OSH_COMMIT | default('176b412072969f982386db9560b6f50fcb7e0148') }}"

View File

@ -19,7 +19,7 @@ osh_params:
container_distro_version: focal container_distro_version: focal
# feature_gates: # feature_gates:
site: airskiff site: airskiff
HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.13.2-linux-amd64.tar.gz HELM_ARTIFACT_URL: https://get.helm.sh/helm-v3.15.4-linux-amd64.tar.gz
HTK_COMMIT: 6ca83be78013446540b68fd28d0a75d5b2329f40 HTK_COMMIT: 6ca83be78013446540b68fd28d0a75d5b2329f40
OSH_INFRA_COMMIT: 6ca83be78013446540b68fd28d0a75d5b2329f40 OSH_INFRA_COMMIT: 6ca83be78013446540b68fd28d0a75d5b2329f40
OSH_COMMIT: 176b412072969f982386db9560b6f50fcb7e0148 OSH_COMMIT: 176b412072969f982386db9560b6f50fcb7e0148

View File

@ -32,7 +32,7 @@
FEATURE_GATES: "{{ osh_params.feature_gates | default('') }}" FEATURE_GATES: "{{ osh_params.feature_gates | default('') }}"
RUN_HELM_TESTS: "{{ run_helm_tests | default('yes') }}" RUN_HELM_TESTS: "{{ run_helm_tests | default('yes') }}"
PL_SITE: "{{ site | default('airskiff') }}" PL_SITE: "{{ site | default('airskiff') }}"
HELM_ARTIFACT_URL: "{{ HELM_ARTIFACT_URL | default('https://get.helm.sh/helm-v3.13.2-linux-amd64.tar.gz') }}" HELM_ARTIFACT_URL: "{{ HELM_ARTIFACT_URL | default('https://get.helm.sh/helm-v3.15.4-linux-amd64.tar.gz') }}"
HTK_COMMIT: "{{ HTK_COMMIT | default('6ca83be78013446540b68fd28d0a75d5b2329f40') }}" HTK_COMMIT: "{{ HTK_COMMIT | default('6ca83be78013446540b68fd28d0a75d5b2329f40') }}"
OSH_INFRA_COMMIT: "{{ OSH_INFRA_COMMIT | default('6ca83be78013446540b68fd28d0a75d5b2329f40') }}" OSH_INFRA_COMMIT: "{{ OSH_INFRA_COMMIT | default('6ca83be78013446540b68fd28d0a75d5b2329f40') }}"
OSH_COMMIT: "{{ OSH_COMMIT | default('176b412072969f982386db9560b6f50fcb7e0148') }}" OSH_COMMIT: "{{ OSH_COMMIT | default('176b412072969f982386db9560b6f50fcb7e0148') }}"