Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .cruft.json
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@
"add_matrix": "y",
"add_go_unit": "n",
"automerge_patch": "y",
"automerge_patch_v0": "n",
"automerge_patch_v0": "y",
"automerge_patch_regexp_blocklist": "",
"automerge_patch_v0_regexp_allowlist": "",
"automerge_minor_regexp_allowlist": "",
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@
/helmcharts
/manifests
/vendor
/jsonnetfile.json
/jsonnetfile.lock.json
/crds
/compiled
Expand Down
59 changes: 59 additions & 0 deletions class/defaults.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,63 @@ parameters:
rollout_operator:
=_metadata:
multi_tenant: true

namespace: syn-rollout-operator

charts:
rollout-operator:
source: https://grafana.github.io/helm-charts
version: v0.47.0

images:
rolloutOperator:
registry: docker.io
repository: grafana/rollout-operator

resources:
requests:
cpu: 100m
memory: 100Mi
limits:
memory: 200Mi

webhooks:
# Note that the webhooks installs rollout-operator CRDs.
enabled: true
timeoutSeconds: 10
failurePolicy: 'Fail'
selfSignedCertSecretName: 'certificate'
objectSelector: {}
namespaceSelector:
matchLabels:
rollout-operator.syn.tools/allow: ''
# matchExpressions:
# - key: rollout-operator.syn.tools/allow
# operator: Exists

monitoring: true
alerts:
rules:
'alert:SYN_IncorrectWebhookConfigurationFailurePolicy':
expr: 'count by(type, webhook, namespace) (kube_validating_webhook_failure_policy{policy="Ignore", webhook=~"^(pod-eviction|zpdb-validation).+"} > 0)'
for: 5m
labels:
severity: warning
annotations:
summary: 'A validating or mutating rollout-operator webhook has an Ignore policy set. This should be set to Fail.'
'alert:SYN_BadZoneAwarePodDisruptionBudgetConfiguration':
expr: 'sum by (job, namespace)(rate(rollout_operator_zpdb_configurations_observed_total{result="invalid"}[5m])) > 0'
for: 5m
labels:
severity: warning
annotations:
summary: 'An invalid zone aware pod disruption budget configuration has been observed.'
'alert:SYN_HighNumberInflightZpdbRequests':
expr: 'avg_over_time(rollout_operator_zpdb_inflight_eviction_requests[5m]) > 10'
for: 5m
labels:
severity: warning
annotations:
summary: 'A sustained number of inflight ZPDB eviction requests has been observed.'

helmValues: {}
24 changes: 24 additions & 0 deletions class/rollout-operator.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
parameters:
kapitan:
dependencies:
- type: helm
source: ${rollout_operator:charts:rollout-operator:source}
chart_name: rollout-operator
version: ${rollout_operator:charts:rollout-operator:version}
output_path: ${_base_directory}/helmcharts/rollout-operator/${rollout_operator:charts:rollout-operator:version}

compile:
- input_paths:
- ${_base_directory}/component/app.jsonnet
Expand All @@ -9,3 +16,20 @@ parameters:
- ${_base_directory}/component/main.jsonnet
input_type: jsonnet
output_path: rollout-operator/

# Helm chart
- input_type: jsonnet
input_paths:
- ${_base_directory}/component/helm.jsonnet
output_path: ${_base_directory}/helmcharts/rollout-operator/${rollout_operator:charts:rollout-operator:version}/
- input_type: helm
output_type: yaml
input_paths:
- ${_base_directory}/helmcharts/rollout-operator/${rollout_operator:charts:rollout-operator:version}
output_path: ${_instance}/10_rollout_operator
helm_values_files:
- ${_base_directory}/helmcharts/rollout-operator/${rollout_operator:charts:rollout-operator:version}/values-component.yaml
- ${_base_directory}/helmcharts/rollout-operator/${rollout_operator:charts:rollout-operator:version}/values-overrides.yaml
helm_params:
name: rollout-operator
namespace: ${rollout_operator:namespace}
10 changes: 9 additions & 1 deletion component/app.jsonnet
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,15 @@ local inv = kap.inventory();
local params = inv.parameters.rollout_operator;
local argocd = import 'lib/argocd.libjsonnet';

local app = argocd.App('rollout-operator', params.namespace);
local app = argocd.App('rollout-operator', params.namespace) {
spec+: {
syncPolicy+: {
syncOptions+: [
'ServerSideApply=true',
],
},
},
};

local appPath =
local project = std.get(std.get(app, 'spec', {}), 'project', 'syn');
Expand Down
52 changes: 52 additions & 0 deletions component/helm.jsonnet
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
local com = import 'lib/commodore.libjsonnet';
local kap = import 'lib/kapitan.libjsonnet';
local inv = kap.inventory();

// The hiera parameters for the component
local params = inv.parameters.rollout_operator;
local isOpenshift = std.member([ 'openshift4', 'oke' ], inv.parameters.facts.distribution);

local values = {
global: {
commonLabels: {
'app.kubernetes.io/managed-by': 'commodore',
'app.kubernetes.io/name': 'rollout-operator',
},
},
image: {
registry: params.images.rolloutOperator.registry,
repository: params.images.rolloutOperator.repository,
[if std.objectHas(params.images.rolloutOperator, 'tag') then 'tag']: params.images.rolloutOperator.tag,
},
resources: params.resources,
webhooks: {
[key]: params.webhooks[key]
for key in std.objectFields(params.webhooks)
if key != 'namespaceSelector'
},
namespaceSelector: params.webhooks.namespaceSelector,
[if !isOpenshift then 'podSecurityContext']: {
fsGroup: 10001,
runAsGroup: 10001,
runAsNonRoot: true,
runAsUser: 10001,
seccompProfile: {
type: 'RuntimeDefault',
},
},
securityContext: {
readOnlyRootFilesystem: true,
capabilities: {
drop: [ 'ALL' ],
},
allowPrivilegeEscalation: false,
},
serviceMonitor: {
enabled: params.monitoring,
},
};

{
'values-component': values,
'values-overrides': params.helmValues,
}
28 changes: 28 additions & 0 deletions component/main.jsonnet
Original file line number Diff line number Diff line change
@@ -1,10 +1,38 @@
// main template for rollout-operator
local kap = import 'lib/kapitan.libjsonnet';
local kube = import 'lib/kube.libjsonnet';
local prom = import 'lib/prom.libsonnet';
local inv = kap.inventory();

// The hiera parameters for the component
local params = inv.parameters.rollout_operator;
local isOpenshift = std.member([ 'openshift4', 'oke' ], inv.parameters.facts.distribution);

local namespace = {
apiVersion: 'v1',
kind: 'Namespace',
metadata: {
labels: {
'app.kubernetes.io/managed-by': 'commodore',
'app.kubernetes.io/name': params.namespace,
[if isOpenshift then 'openshift.io/cluster-monitoring']: 'true',
},
name: params.namespace,
},
};

local prometheusRules = prom.generateRules('rollout-operator', { 'rollout-operator.rules': params.alerts.rules }) {
metadata+: {
labels+: {
'app.kubernetes.io/managed-by': 'commodore',
'app.kubernetes.io/name': 'rollout-operator',
},
namespace: params.namespace,
},
};

// Define outputs below
{
'00_namespace': namespace,
[if params.monitoring then '20_prometheus_rule']: prometheusRules,
}
Loading
Loading