1e1789f6d1
This change allows configuration of the http and https listeners used by the supervisor. TCP (IPv4 and IPv6 with any interface and port) and Unix domain socket based listeners are supported. Listeners may also be disabled. Binding the http listener to TCP addresses other than 127.0.0.1 or ::1 is deprecated. The deployment now uses https health checks. The supervisor is always able to complete a TLS connection with the use of a bootstrap certificate that is signed by an in-memory certificate authority. To support sidecar containers used by service meshes, Unix domain socket based listeners include ACLs that allow writes to the socket file from any runAsUser specified in the pod's containers. Signed-off-by: Monis Khan <mok@vmware.com>
81 lines
2.0 KiB
YAML
81 lines
2.0 KiB
YAML
#! Copyright 2020-2021 the Pinniped contributors. All Rights Reserved.
|
|
#! SPDX-License-Identifier: Apache-2.0
|
|
|
|
#@ load("@ytt:data", "data")
|
|
#@ load("@ytt:template", "template")
|
|
|
|
#@ def defaultResourceName():
|
|
#@ return data.values.app_name
|
|
#@ end
|
|
|
|
#@ def defaultResourceNameWithSuffix(suffix):
|
|
#@ return data.values.app_name + "-" + suffix
|
|
#@ end
|
|
|
|
#@ def pinnipedDevAPIGroupWithPrefix(prefix):
|
|
#@ return prefix + "." + data.values.api_group_suffix
|
|
#@ end
|
|
|
|
#@ def namespace():
|
|
#@ if data.values.into_namespace:
|
|
#@ return data.values.into_namespace
|
|
#@ else:
|
|
#@ return data.values.namespace
|
|
#@ end
|
|
#@ end
|
|
|
|
#@ def defaultLabel():
|
|
app: #@ data.values.app_name
|
|
#@ end
|
|
|
|
#@ def deploymentPodLabel():
|
|
deployment.pinniped.dev: supervisor
|
|
#@ end
|
|
|
|
#@ def labels():
|
|
_: #@ template.replace(defaultLabel())
|
|
_: #@ template.replace(data.values.custom_labels)
|
|
#@ end
|
|
|
|
#@ def getAndValidateLogLevel():
|
|
#@ log_level = data.values.log_level
|
|
#@ if log_level != "info" and log_level != "debug" and log_level != "trace" and log_level != "all":
|
|
#@ fail("log_level '" + log_level + "' is invalid")
|
|
#@ end
|
|
#@ return log_level
|
|
#@ end
|
|
|
|
#@ def getPinnipedConfigMapData():
|
|
#@ config = {
|
|
#@ "apiGroupSuffix": data.values.api_group_suffix,
|
|
#@ "names": {
|
|
#@ "defaultTLSCertificateSecret": defaultResourceNameWithSuffix("default-tls-certificate"),
|
|
#@ },
|
|
#@ "labels": labels(),
|
|
#@ }
|
|
#@ if data.values.log_level:
|
|
#@ config["logLevel"] = getAndValidateLogLevel()
|
|
#@ end
|
|
#@ if data.values.endpoints:
|
|
#@ config["endpoints"] = data.values.endpoints
|
|
#@ end
|
|
#@ return config
|
|
#@ end
|
|
|
|
#@ def getattr_safe(val, *args):
|
|
#@ out = None
|
|
#@ for arg in args:
|
|
#@ if not hasattr(val, arg):
|
|
#@ return None
|
|
#@ end
|
|
#@ out = getattr(val, arg)
|
|
#@ val = out
|
|
#@ end
|
|
#@ return out
|
|
#@ end
|
|
|
|
#@ def hasUnixNetworkEndpoint():
|
|
#@ return getattr_safe(data.values.endpoints, "http", "network") == "unix" or \
|
|
#@ getattr_safe(data.values.endpoints, "https", "network") == "unix"
|
|
#@ end
|