Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update common #90

Merged
merged 184 commits into from
Aug 1, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
184 commits
Select commit Hold shift + click to select a range
1cb3f09
Updated namespaces template to include labels and annotations functio…
claudiol Mar 21, 2023
e68b7d9
Added schema validation to support additional formal for labels and a…
claudiol Mar 21, 2023
8aa8396
Updated the values-example.yaml to include new format for namespaces
claudiol Mar 21, 2023
6b55045
Updated Changes.md to include new namespaces functionality.
claudiol Mar 21, 2023
7565648
Updating CI tests
claudiol Mar 21, 2023
185d11a
Fixed Markdown errors
claudiol Mar 21, 2023
c2ecb2a
Add an experimental letsencypt chart
mbaldessari Mar 14, 2023
7572b82
Do not run kubeconform on the certificate stuff just yet
mbaldessari Apr 3, 2023
527ca41
Fix up kustomize example
mbaldessari Apr 11, 2023
c154929
Merge pull request #293 from mbaldessari/fix-customize
mbaldessari Apr 11, 2023
3a77a96
Upgrade vault-helm to v0.24.0
mbaldessari Apr 11, 2023
3be58c7
Merge pull request #294 from mbaldessari/vault-helm-0.24.0
mbaldessari Apr 11, 2023
817bf1f
Add a hello-world ansible playbook example
mbaldessari Apr 15, 2023
248ac46
Inject ANSIBLE_CONFIG in make ansible-lint
mbaldessari Apr 15, 2023
bcc7b24
Use new ansible-lint action
mbaldessari Apr 15, 2023
879737f
Fix some ansible-lint warnings
mbaldessari Apr 15, 2023
12fd2f8
Fix up python versions
mbaldessari Apr 15, 2023
a3b22b5
Skip cannot find role error
mbaldessari Apr 15, 2023
8a63118
Merge pull request #297 from mbaldessari/hello-world-ansible
mbaldessari Apr 15, 2023
dde9699
Added health check for pvc resource in argocd.yaml
day0hero Apr 20, 2023
f2010a3
adding tests
day0hero Apr 20, 2023
e06ad88
Update super-linter image to latest
mbaldessari Apr 20, 2023
3545945
Update super-linter image to latest
mbaldessari Apr 20, 2023
ce520d2
Merge pull request #299 from mbaldessari/superlinter-v5
mbaldessari Apr 20, 2023
adb4a67
Merge branch 'main' of https://github.com/hybrid-cloud-patterns/common
mbaldessari Apr 20, 2023
7fa15b1
Update CI workflows
mbaldessari Apr 20, 2023
17a1402
Merge pull request #300 from mbaldessari/ci-update
mbaldessari Apr 20, 2023
6b88bcd
updated template with why implemented comment
day0hero Apr 20, 2023
d6ab881
Add dependabot settings for github actions
mbaldessari Apr 21, 2023
5978a08
Merge pull request #301 from mbaldessari/dependabot
mbaldessari Apr 21, 2023
eaf2619
Merge pull request #287 from mbaldessari/letsencrypt
mbaldessari Apr 21, 2023
8faea73
adding tests
day0hero Apr 21, 2023
d3b6faf
- Added functionality to support the following format for labels and …
claudiol Apr 21, 2023
3c60aa1
Merge branch 'main' into namespace-additional-properties
claudiol Apr 21, 2023
9d6fc02
Fixed CI Issues
claudiol Apr 21, 2023
2863999
Applying @claudiol recommendation
day0hero Apr 21, 2023
fd004fb
make test
day0hero Apr 21, 2023
90602fc
Merge pull request #298 from hybrid-cloud-patterns/argocd-pvc-healthc…
mbaldessari Apr 22, 2023
d1cf543
Avoid exited containers proliferation
Apr 27, 2023
cc44bff
Merge pull request #302 from beelzetron/feature/clean-podman-exited-c…
mbaldessari Apr 27, 2023
37c8f3a
Handling of pre-release builds is too complex for a helm chart
beekhof Apr 28, 2023
d6b2b0d
Merge branch 'main' into namespace-additional-properties
claudiol May 3, 2023
3c81c48
Fixing issues with operator groups
claudiol May 3, 2023
fa9f2dc
Adding CI test
claudiol May 3, 2023
a0e2d91
Updated operator group template
claudiol May 3, 2023
3f6d9b5
Updating CI issues
claudiol May 3, 2023
6566688
Removed duplicate code for operatorgroup by using multiple conditions
claudiol May 5, 2023
b855239
Merge pull request #283 from claudiol/namespace-additional-properties
mbaldessari May 10, 2023
c7dadbf
Allow overriding the pattern's name
mbaldessari May 15, 2023
7ccd29c
Merge pull request #303 from mbaldessari/name
mhjacks May 15, 2023
a6bb073
Add precise instruction to upgrade the vault subchart
mbaldessari May 16, 2023
ea7186e
Upgrade vault-helm to v0.24.1
mbaldessari May 16, 2023
c09126f
Add an item to README.md
mbaldessari May 16, 2023
70b778c
Fix up common/ tests
mbaldessari May 16, 2023
ee59eee
Fix super linter
mbaldessari May 16, 2023
07acbc3
Merge pull request #304 from mbaldessari/vault-helm-0.24.1
mbaldessari May 16, 2023
0e661bf
Set gitOpsSpec.operatorSource
mbaldessari May 18, 2023
d9db633
Introduce EXTRA_HELM_OPTS
mbaldessari May 18, 2023
8bfb05d
Disable var-naming[no-role-prefix] in ansible lint
mbaldessari May 18, 2023
2fff431
Merge pull request #306 from mbaldessari/catalogsource
mbaldessari May 18, 2023
b4e5967
Add new ansible role to deal with IIBs
mbaldessari May 16, 2023
5cbc2c0
Simplify load-iib target
mbaldessari May 16, 2023
bb97c58
Add templates folder
mbaldessari May 16, 2023
65dda37
Fix a couple of linting warnings
mbaldessari May 16, 2023
4dfeecb
Fix some super-linter complaints
mbaldessari May 16, 2023
33dfdb3
Skip the iib-ci playbook
mbaldessari May 16, 2023
93fd8c8
Drop var-naming[no-role-prefix] linter
mbaldessari May 16, 2023
6263afe
Allow for multiple images when calling load-iib
mbaldessari May 17, 2023
c776ed0
Add help for load-iib
mbaldessari May 17, 2023
b6b4836
Output index_image in make
mbaldessari May 17, 2023
51b9fb4
Output index_image in make (2)
mbaldessari May 17, 2023
7567a73
Set facts later in the playbook not in defaults/
mbaldessari May 17, 2023
ff6b73f
Fix how we export vars in make load-iib
mbaldessari May 17, 2023
7dfa5cf
Fix how we export vars in make load-iib (2)
mbaldessari May 17, 2023
5e51a63
Use machineCount to register the number of nodes that need to be ready
mbaldessari May 17, 2023
1b80705
Add helpful debug messages
mbaldessari May 17, 2023
aef9717
Add | on shell now that we call pipefail
mbaldessari May 17, 2023
14209b3
Test dropping nevercontact source
mbaldessari May 17, 2023
7d17348
Skip insecure tls when logging in
mbaldessari May 18, 2023
dbdbc8c
Also allow gchr.io
mbaldessari May 18, 2023
0355fa4
Revert "Test dropping nevercontact source"
mbaldessari May 18, 2023
47855e0
Fix typo
mbaldessari May 18, 2023
49f018a
Clarify instructions in the README file
mbaldessari May 18, 2023
d1dc09f
Automate the channel example
mbaldessari May 18, 2023
729232a
Find out KUBEADMINAPI programmatically
mbaldessari May 18, 2023
d4eb914
Use command instead of shell
mbaldessari May 18, 2023
f73f75d
Do not grep for operator bundle unless it is the gitops operator
mbaldessari May 18, 2023
b660f93
Also whitelist ghcr.io
mbaldessari May 18, 2023
41dc747
Fetch the operator bundle itself in a more robust way
mbaldessari May 18, 2023
2a941fb
Add more mirrors
mbaldessari May 18, 2023
a4e232b
Some more work to support MCE
mbaldessari May 19, 2023
45912f1
Cleanup spacing
mbaldessari May 19, 2023
86ac7c2
Fix super-linter
mbaldessari May 19, 2023
d713e7b
Move task in right folder
mbaldessari May 19, 2023
09e5389
Drop last mention of operator instead of item
mbaldessari May 19, 2023
f4b54ae
Merge pull request #305 from mbaldessari/iib
mbaldessari May 19, 2023
45a5e25
Improve the grepping for the operator bundle
mbaldessari May 22, 2023
8239ea4
Merge pull request #307 from mbaldessari/fix-iib1
mbaldessari May 22, 2023
3c29969
Drop display_skipped_hosts
mbaldessari May 22, 2023
65c512a
Merge pull request #308 from mbaldessari/ansible-cfg
mbaldessari May 22, 2023
ff1eacf
Be more specific about the steps in the README
mbaldessari May 22, 2023
44f6d57
Upgrade ESO to v0.8.2
mbaldessari May 22, 2023
06698b3
Update README.md
mbaldessari May 22, 2023
9abbef7
Update tests after eso 0.8.2 upgrade
mbaldessari May 22, 2023
b0e08e0
Merge pull request #309 from mbaldessari/eso-0.8.2
mbaldessari May 22, 2023
f672950
Move to new spec format for dex/sso
mbaldessari Apr 7, 2023
8ed17fc
Disable ArgoCD from kubeconform
mbaldessari Apr 7, 2023
460cc67
Merge pull request #290 from mbaldessari/modernize-argo-sso
mbaldessari May 22, 2023
bf56440
Add a short line about username/token for the iib role on OCP <= 4.12
mbaldessari May 24, 2023
576c246
Merge pull request #310 from mbaldessari/readme-iib
mbaldessari May 24, 2023
dfc504e
Drop https:// from podman login
mbaldessari May 24, 2023
e01dcda
Merge pull request #311 from mbaldessari/podman-version-
mbaldessari May 24, 2023
1edf4da
Set the mce-subscription-spec annotation
mbaldessari May 25, 2023
240d04b
Merge pull request #312 from mbaldessari/mce-sub
mbaldessari May 25, 2023
5396871
Fix typo in README for iib
mbaldessari May 25, 2023
058d5c6
Simplify the README a bit
mbaldessari May 25, 2023
e20c287
Merge pull request #313 from mbaldessari/iib-fixes
mbaldessari May 25, 2023
0432536
Add support for extraParams being passed down to all applications
mbaldessari May 30, 2023
bb8e98b
Merge pull request #314 from mbaldessari/fix-extraparams
mbaldessari May 30, 2023
48126e7
Add a lookup playbook to figure out IIB numbers
mbaldessari Jun 1, 2023
ff8bea5
Merge pull request #315 from mbaldessari/lookup
mbaldessari Jun 1, 2023
b1070a1
Allow overriding channel and source when installing the patterns-oper…
mbaldessari Jun 1, 2023
35f79c0
Merge pull request #316 from mbaldessari/pattern-index
mbaldessari Jun 2, 2023
8f3c407
Fix small typo in iib instructions
mbaldessari Jun 6, 2023
b6ee6ed
Merge pull request #317 from mbaldessari/fixtypo1
mbaldessari Jun 6, 2023
6116964
Drop a redirect and up retries when pushing the IIB to the internal r…
mbaldessari Jun 7, 2023
6923648
Merge pull request #318 from mbaldessari/drop-iib-log
mbaldessari Jun 7, 2023
6e6f258
Update ESO to v0.8.3
mbaldessari Jun 15, 2023
18d2ac2
Merge pull request #319 from mbaldessari/eso-0.8.3
mbaldessari Jun 15, 2023
2797699
WIP add presync for eso that waits for vault to be up
mbaldessari Jun 15, 2023
ab5532a
Add tests
mbaldessari Jun 15, 2023
d4d3fe1
Fix image and comment
mbaldessari Jun 15, 2023
598bc74
Adding rbac to support the vault sa checking on the vault-0 pod status.
day0hero Jun 26, 2023
64e9dc7
Make Test
day0hero Jun 26, 2023
e296fb0
Merge pull request #321 from hybrid-cloud-patterns/presync
day0hero Jun 26, 2023
1895a73
Revert "Make Test"
mbaldessari Jul 7, 2023
08eee55
Revert "Adding rbac to support the vault sa checking on the vault-0 p…
mbaldessari Jul 7, 2023
c5aa3d2
Revert "Fix image and comment"
mbaldessari Jul 7, 2023
6d4a481
Revert "Add tests"
mbaldessari Jul 7, 2023
3bf245b
Revert "WIP add presync for eso that waits for vault to be up"
mbaldessari Jul 7, 2023
0ae561b
Increase the default retry limit when syncing
mbaldessari Jul 7, 2023
66d456d
Add Changes.md entry
mbaldessari Jul 8, 2023
0c1d103
Merge pull request #323 from mbaldessari/retry-final
mbaldessari Jul 8, 2023
54056c7
Split off global helm variables to a helper definition
mbaldessari Jul 10, 2023
fdee136
Switch ApplicationSets to use the newly-introduced helpers
mbaldessari Jul 10, 2023
4e1f360
Split off valueFiles to _helpers.tbl
mbaldessari Jul 10, 2023
35e7990
Switch applicationsets to use the new helper
mbaldessari Jul 10, 2023
e85c3ab
Drop some older comments
mbaldessari Jul 11, 2023
eb791ba
Merge pull request #324 from mbaldessari/cleanups
mbaldessari Jul 11, 2023
16fab03
Tweak the load secret debug message to be clearer
mbaldessari Jul 13, 2023
5219947
Merge pull request #325 from mbaldessari/fix-found-fileoutput
mbaldessari Jul 13, 2023
6e31814
Check if the KUBECONFIG file is pointing outside of the HOME folder
mbaldessari Jul 13, 2023
4193c08
Include an example SNO cluster pool in the tests
beekhof Jul 14, 2023
ad39f4d
Enforce lowercase names for cluster claims
beekhof Jul 14, 2023
b087e87
Avoid mixing yaml and json in the OCP install-config
beekhof Jul 14, 2023
38d83ec
Update provisioning tests
beekhof Jul 14, 2023
4a0d715
Merge pull request #327 from beekhof/provision-sno
beekhof Jul 14, 2023
fa6865c
Sanely handle cluster pools with no clusters (yet)
beekhof Jul 14, 2023
b071b89
Merge pull request #328 from hybrid-cloud-patterns/standby-pool
mbaldessari Jul 14, 2023
c220a68
Clustergroup Chart.yaml name change
mbaldessari Jul 16, 2023
6e6824d
Merge pull request #330 from mbaldessari/clustergroup-name
mbaldessari Jul 16, 2023
29a5843
Merge pull request #326 from mbaldessari/small-uxfix
day0hero Jul 18, 2023
21c534c
Fix the clusterPoolName in clusterClaims
mbaldessari Jul 19, 2023
e0d7954
Merge pull request #331 from mbaldessari/clusterclaim-fix
mbaldessari Jul 19, 2023
4c05974
Add some comments to make if/else and loops clearer
mbaldessari Jul 24, 2023
36d679a
Merge pull request #332 from mbaldessari/comments
mbaldessari Jul 24, 2023
dd3cdcb
Add some more comments in applications.yaml
mbaldessari Jul 27, 2023
5f33f33
Add a default for options applicationRetryLimit
mbaldessari Jul 27, 2023
91f3ef0
Split out values files to a helper for the acm chart
mbaldessari Jul 27, 2023
17697e5
Fix up tests
mbaldessari Jul 27, 2023
3bd8487
Merge pull request #333 from mbaldessari/cleanup
mbaldessari Jul 27, 2023
669ff92
Fix sa/namespace mixup in vault_spokes_init
stocky37 Jul 28, 2023
d7994cb
Merge pull request #334 from stocky37/fix-vault-unseal-ansible
mbaldessari Jul 30, 2023
5cb41a3
Update local patch
mbaldessari Jul 31, 2023
9d2df97
Update ESO to 0.8.5
mbaldessari Jul 31, 2023
e720991
Tweak ESO UBI images
mbaldessari Jul 31, 2023
15363f6
Merge pull request #335 from mbaldessari/fix-eso
mbaldessari Jul 31, 2023
4cbef5e
Upgrade vault-helm to v0.25.0
mbaldessari Jul 31, 2023
49728fa
Error out from load-iib when INDEX_IMAGES is undefined
mbaldessari Aug 1, 2023
bc74b85
Merge pull request #337 from mbaldessari/iib-ux
mbaldessari Aug 1, 2023
35e64a1
Merge pull request #336 from mbaldessari/vault-helm-0.25.0
mbaldessari Aug 1, 2023
eb45d81
Removed previous version of common to convert to subtree from https:/…
day0hero Aug 1, 2023
ffb008c
Add 'common/' from commit '35e64a102db0fb7fe3903acff56d3b4be9cf02b7'
day0hero Aug 1, 2023
3444d34
Make test
day0hero Aug 1, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions common/Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,9 @@ load-iib: ## CI target to install Index Image Bundles
for IIB in $(shell echo $(INDEX_IMAGES) | tr ',' '\n'); do \
INDEX_IMAGE="$${IIB}" ansible-playbook common/ansible/playbooks/iib-ci/iib-ci.yaml; \
done; \
else \
echo "No INDEX_IMAGES defined. Bailing out"; \
exit 1; \
fi


Expand Down
Binary file not shown.
2 changes: 1 addition & 1 deletion common/hashicorp-vault/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,5 +6,5 @@ name: hashicorp-vault
version: 0.0.1
dependencies:
- name: vault
version: "0.24.1"
version: "0.25.0"
repository: "https://helm.releases.hashicorp.com"
Binary file removed common/hashicorp-vault/charts/vault-0.24.1.tgz
Binary file not shown.
Binary file added common/hashicorp-vault/charts/vault-0.25.0.tgz
Binary file not shown.
2 changes: 1 addition & 1 deletion common/hashicorp-vault/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -49,4 +49,4 @@ vault:
termination: "reencrypt"
image:
repository: "registry.connect.redhat.com/hashicorp/vault"
tag: "1.13.1-ubi"
tag: "1.14.0-ubi"
Original file line number Diff line number Diff line change
Expand Up @@ -8140,25 +8140,6 @@ rules:
- "update"
- "patch"
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-vault-rbac-role.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: view-pods
namespace: vault
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-15"
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
---
# Source: golang-external-secrets/charts/external-secrets/templates/rbac.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
Expand All @@ -8180,25 +8161,6 @@ subjects:
name: golang-external-secrets
namespace: "default"
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-vault-rbac-rolebinding.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: view-pods-rb
namespace: vault
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-15"
subjects:
- kind: ServiceAccount
name: vault
namespace: vault
apiGroup: ""
roleRef:
kind: Role
name: view-pods
apiGroup: rbac.authorization.k8s.io
---
# Source: golang-external-secrets/charts/external-secrets/templates/webhook-service.yaml
apiVersion: v1
kind: Service
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8140,25 +8140,6 @@ rules:
- "update"
- "patch"
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-vault-rbac-role.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: view-pods
namespace: vault
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-15"
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
---
# Source: golang-external-secrets/charts/external-secrets/templates/rbac.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
Expand All @@ -8180,25 +8161,6 @@ subjects:
name: golang-external-secrets
namespace: "default"
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-vault-rbac-rolebinding.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: view-pods-rb
namespace: vault
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-15"
subjects:
- kind: ServiceAccount
name: vault
namespace: vault
apiGroup: ""
roleRef:
kind: Role
name: view-pods
apiGroup: rbac.authorization.k8s.io
---
# Source: golang-external-secrets/charts/external-secrets/templates/webhook-service.yaml
apiVersion: v1
kind: Service
Expand Down Expand Up @@ -8396,32 +8358,6 @@ spec:
secret:
secretName: golang-external-secrets-webhook
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-presync.yaml
apiVersion: batch/v1
kind: Job
metadata:
annotations:
argocd.argoproj.io/hook: PreSync
name: job-wait-for-vault
# By placing the job in the vault namespace we can avoid dealing with RBACs
namespace: vault
spec:
template:
spec:
containers:
- image: image-registry.openshift-image-registry.svc:5000/openshift/cli:latest
command:
- /bin/bash
- -c
- |
oc wait --for=condition=Ready=true pods -n vault vault-0 --timeout=900s
name: wait-for-healthy-vault
dnsPolicy: ClusterFirst
restartPolicy: Never
serviceAccount: vault
serviceAccountName: vault
terminationGracePeriodSeconds: 60
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-secretstore.yaml
apiVersion: external-secrets.io/v1beta1
kind: ClusterSecretStore
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8140,25 +8140,6 @@ rules:
- "update"
- "patch"
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-vault-rbac-role.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: view-pods
namespace: vault
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-15"
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
---
# Source: golang-external-secrets/charts/external-secrets/templates/rbac.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
Expand All @@ -8180,25 +8161,6 @@ subjects:
name: golang-external-secrets
namespace: "default"
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-vault-rbac-rolebinding.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: view-pods-rb
namespace: vault
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-15"
subjects:
- kind: ServiceAccount
name: vault
namespace: vault
apiGroup: ""
roleRef:
kind: Role
name: view-pods
apiGroup: rbac.authorization.k8s.io
---
# Source: golang-external-secrets/charts/external-secrets/templates/webhook-service.yaml
apiVersion: v1
kind: Service
Expand Down Expand Up @@ -8396,32 +8358,6 @@ spec:
secret:
secretName: golang-external-secrets-webhook
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-presync.yaml
apiVersion: batch/v1
kind: Job
metadata:
annotations:
argocd.argoproj.io/hook: PreSync
name: job-wait-for-vault
# By placing the job in the vault namespace we can avoid dealing with RBACs
namespace: vault
spec:
template:
spec:
containers:
- image: image-registry.openshift-image-registry.svc:5000/openshift/cli:latest
command:
- /bin/bash
- -c
- |
oc wait --for=condition=Ready=true pods -n vault vault-0 --timeout=900s
name: wait-for-healthy-vault
dnsPolicy: ClusterFirst
restartPolicy: Never
serviceAccount: vault
serviceAccountName: vault
terminationGracePeriodSeconds: 60
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-secretstore.yaml
apiVersion: external-secrets.io/v1beta1
kind: ClusterSecretStore
Expand Down
64 changes: 0 additions & 64 deletions common/tests/golang-external-secrets-naked.expected.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8140,25 +8140,6 @@ rules:
- "update"
- "patch"
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-vault-rbac-role.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: view-pods
namespace: vault
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-15"
rules:
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
---
# Source: golang-external-secrets/charts/external-secrets/templates/rbac.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
Expand All @@ -8180,25 +8161,6 @@ subjects:
name: golang-external-secrets
namespace: "default"
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-vault-rbac-rolebinding.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: view-pods-rb
namespace: vault
annotations:
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/sync-wave: "-15"
subjects:
- kind: ServiceAccount
name: vault
namespace: vault
apiGroup: ""
roleRef:
kind: Role
name: view-pods
apiGroup: rbac.authorization.k8s.io
---
# Source: golang-external-secrets/charts/external-secrets/templates/webhook-service.yaml
apiVersion: v1
kind: Service
Expand Down Expand Up @@ -8396,32 +8358,6 @@ spec:
secret:
secretName: golang-external-secrets-webhook
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-presync.yaml
apiVersion: batch/v1
kind: Job
metadata:
annotations:
argocd.argoproj.io/hook: PreSync
name: job-wait-for-vault
# By placing the job in the vault namespace we can avoid dealing with RBACs
namespace: vault
spec:
template:
spec:
containers:
- image: image-registry.openshift-image-registry.svc:5000/openshift/cli:latest
command:
- /bin/bash
- -c
- |
oc wait --for=condition=Ready=true pods -n vault vault-0 --timeout=900s
name: wait-for-healthy-vault
dnsPolicy: ClusterFirst
restartPolicy: Never
serviceAccount: vault
serviceAccountName: vault
terminationGracePeriodSeconds: 60
---
# Source: golang-external-secrets/templates/golang-external-secrets-hub-secretstore.yaml
apiVersion: external-secrets.io/v1beta1
kind: ClusterSecretStore
Expand Down
Loading
Loading