Merge "Upgrade FluxCD Helm and Source Controllers."

This commit is contained in:
Zuul
2023-08-30 21:08:22 +00:00
committed by Gerrit Code Review
8 changed files with 5853 additions and 1057 deletions

View File

@@ -20,8 +20,8 @@ spec:
spec:
containers:
- name: manager
command: ["/sbin/tini"]
args: ["--", "/bin/sh", "-c", "helm-controller --watch-all-namespaces --log-level=debug --log-encoding=console --enable-leader-election 2>&1 | tee -a /var/log/helm-controller.log"]
command: ["/bin/sh"]
args: ["-c", "helm-controller --watch-all-namespaces --log-level=debug --log-encoding=console --enable-leader-election 2>&1 | tee -a /var/log/helm-controller.log"]
env:
- name: RUNTIME_NAMESPACE
valueFrom:
@@ -53,7 +53,13 @@ spec:
memory: 64Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
volumeMounts:
- mountPath: /tmp
name: temp
@@ -141,7 +147,13 @@ spec:
memory: 64Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
volumeMounts:
- mountPath: /data
name: data

View File

@@ -1,4 +1,3 @@
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
@@ -36,7 +35,7 @@ rules:
verbs:
- '*'
- apiGroups:
- ""
- ''
resources:
- namespaces
- secrets
@@ -47,14 +46,14 @@ rules:
- list
- watch
- apiGroups:
- ""
- ''
resources:
- events
verbs:
- create
- patch
- apiGroups:
- ""
- ''
resources:
- configmaps
verbs:
@@ -66,7 +65,7 @@ rules:
- patch
- delete
- apiGroups:
- ""
- ''
resources:
- configmaps/status
verbs:
@@ -87,6 +86,46 @@ rules:
- delete
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: flux-edit
namespace: flux-helm
rules:
- apiGroups:
- notification.toolkit.fluxcd.io
- source.toolkit.fluxcd.io
- helm.toolkit.fluxcd.io
- image.toolkit.fluxcd.io
- kustomize.toolkit.fluxcd.io
resources:
- '*'
verbs:
- create
- delete
- deletecollection
- patch
- update
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: flux-view
namespace: flux-helm
rules:
- apiGroups:
- notification.toolkit.fluxcd.io
- source.toolkit.fluxcd.io
- helm.toolkit.fluxcd.io
- image.toolkit.fluxcd.io
- kustomize.toolkit.fluxcd.io
resources:
- '*'
verbs:
- get
- list
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: crd-controller

View File

@@ -2,8 +2,8 @@
fluxcd_namespace: flux-helm
fluxcd_secret_name: default-registry-key
fluxcd_resource_dir: /tmp/fluxcd
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.27.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v0.32.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.35.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v1.0.1
local_registry: registry.local:9001
async_timeout: 240
async_retries: 80

View File

@@ -30,5 +30,5 @@ cert_manager_ctl_img: quay.io/jetstack/cert-manager-ctl:v1.7.1
snapshot_controller_img: quay.io/k8scsi/snapshot-controller:v2.0.0-rc2
rvmc_img: docker.io/starlingx/rvmc:stx.8.0-v1.0.1
pause_img: k8s.gcr.io/pause:3.4.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.27.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v0.32.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.35.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v1.0.1

View File

@@ -29,5 +29,5 @@ cert_manager_ctl_img: quay.io/jetstack/cert-manager-ctl:v1.7.1
snapshot_controller_img: quay.io/k8scsi/snapshot-controller:v2.0.0-rc2
rvmc_img: docker.io/starlingx/rvmc:stx.8.0-v1.0.1
pause_img: k8s.gcr.io/pause:3.4.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.27.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v0.32.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.35.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v1.0.1

View File

@@ -34,5 +34,5 @@ cert_manager_webhook_img_171: quay.io/jetstack/cert-manager-webhook:v1.7.1
snapshot_controller_img: quay.io/k8scsi/snapshot-controller:v2.0.0-rc2
rvmc_img: docker.io/starlingx/rvmc:stx.8.0-v1.0.1
pause_img: k8s.gcr.io/pause:3.4.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.27.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v0.32.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.35.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v1.0.1

View File

@@ -29,5 +29,5 @@ cert_manager_ctl_img: quay.io/jetstack/cert-manager-ctl:v1.7.1
snapshot_controller_img: quay.io/k8scsi/snapshot-controller:v2.0.0-rc2
rvmc_img: docker.io/starlingx/rvmc:stx.8.0-v1.0.1
pause_img: k8s.gcr.io/pause:3.4.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.27.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v0.32.1
flux_helm_controller_img: docker.io/fluxcd/helm-controller:v0.35.0
flux_source_controller_img: docker.io/fluxcd/source-controller:v1.0.1