Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: tunnelclients.deployments.plural.sh
spec:
group: deployments.plural.sh
names:
kind: TunnelClient
plural: tunnelclients
singular: tunnelclient
scope: Namespaced
versions:
- additionalPrinterColumns:
- description: Id registered with the tunnel server
jsonPath: '.spec.tunnelId'
name: Tunnel ID
type: string
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
name: Ready
type: string
name: v1alpha1
schema:
openAPIV3Schema:
description: One local endpoint registered on the FerroTunnel server.
properties:
spec:
description: Desired endpoint for this tunnel.
properties:
tunnelId:
description: DNS label sent to the tunnel server and later used as the HTTP Host.
maxLength: 63
minLength: 1
pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
type: string
upstream:
description: Address the controller can reach from this cluster.
properties:
host:
description: Host or IP of the local service.
minLength: 1
type: string
port:
description: TCP port of the local service.
format: uint16
maximum: 65535.0
minimum: 1.0
type: integer
required:
- host
- port
type: object
required:
- tunnelId
- upstream
type: object
status:
description: Status of a TunnelClient. `Ready` is True once the tunnel id is registered.
nullable: true
properties:
conditions:
items:
description: Condition contains details for one aspect of the current state of this API Resource.
properties:
lastTransitionTime:
description: lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: message is a human readable message indicating details about the transition. This may be an empty string.
type: string
observedGeneration:
description: observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
format: int64
type: integer
reason:
description: reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.
type: string
status:
description: status of the condition, one of True, False, Unknown.
type: string
type:
description: type of condition in CamelCase or in foo.example.com/CamelCase.
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
required:
- spec
title: TunnelClient
type: object
served: true
storage: true
subresources:
status: {}
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: tunnelcontrollers.deployments.plural.sh
spec:
group: deployments.plural.sh
names:
kind: TunnelController
listKind: TunnelControllerList
plural: tunnelcontrollers
singular: tunnelcontroller
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .spec.template.spec.containers[0].image
name: Image
type: string
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
name: Ready
type: string
name: v1alpha1
schema:
openAPIV3Schema:
description: TunnelController runs one FerroTunnel client Deployment for this cluster.
properties:
spec:
description: Optional pod template. The controller creates the Secret and Deployment.
properties:
template:
description: Optional override for the secure default client pod template. Set the ferrotunnel-client image on the tunnel-controller container.
type: object
x-kubernetes-preserve-unknown-fields: true
type: object
status:
description: Observed state of TunnelController.
properties:
conditions:
items:
description: Condition contains details for one aspect of the current state of this API Resource.
properties:
lastTransitionTime:
format: date-time
type: string
message:
type: string
observedGeneration:
format: int64
type: integer
reason:
type: string
status:
type: string
type:
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
4 changes: 4 additions & 0 deletions charts/deployment-operator/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,10 @@ spec:
- -cache-dir={{ .Values.cache.dir }}
- -cache-persist-interval={{ .Values.cache.persistInterval }}
{{- end }}
{{- if .Values.ferrotunnel.enabled }}
- -ferrotunnel-server={{ .Values.ferrotunnel.server }}
- -ferrotunnel-service-account={{ include "deployment-operator.serviceAccountName" . }}
{{- end }}
{{ if .Values.extraArgs }}
{{ toYaml .Values.extraArgs | nindent 10 }}
{{ end }}
Expand Down
8 changes: 7 additions & 1 deletion charts/deployment-operator/templates/secret.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,4 +6,10 @@ metadata:
{{ include "deployment-operator.labels" . | indent 4 }}
type: Opaque
stringData:
DEPLOY_TOKEN: {{ .Values.secrets.deployToken }}
DEPLOY_TOKEN: {{ .Values.secrets.deployToken }}
{{- if .Values.ferrotunnel.enabled }}
FERROTUNNEL_TOKEN: {{ .Values.ferrotunnel.token | quote }}
FERROTUNNEL_CA: {{ .Values.ferrotunnel.ca | b64dec | quote }}
FERROTUNNEL_CERT: {{ .Values.ferrotunnel.cert | b64dec | quote }}
FERROTUNNEL_KEY: {{ .Values.ferrotunnel.key | b64dec | quote }}
{{- end }}
17 changes: 17 additions & 0 deletions charts/deployment-operator/templates/tunnelcontroller.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
{{- $ferrotunnelTag := .Values.ferrotunnel.image.tag | default "master" }}
apiVersion: deployments.plural.sh/v1alpha1
kind: TunnelController
metadata:
name: {{ include "deployment-operator.fullname" . }}-ferrotunnel
labels:
{{- include "deployment-operator.labels" . | nindent 4 }}
spec:
template:
spec:
containers:
- name: tunnel-controller
{{- if .Values.global.registry }}
image: {{ .Values.global.registry }}/ferrotunnel-client:{{ $ferrotunnelTag }}
{{- else }}
image: {{ .Values.ferrotunnel.image.repository }}:{{ $ferrotunnelTag }}
{{- end }}
13 changes: 13 additions & 0 deletions charts/deployment-operator/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -213,3 +213,16 @@ agentk:
serviceMonitor:
# Specifies whether to create a ServiceMonitor resource for collecting Prometheus metrics
enabled: false

# The chart always creates a TunnelController. values.yaml.liquid fills the server, token,
# and client certificate once Console supplies them, and the controller writes the Secret and Deployment.
ferrotunnel:
enabled: false
server: ""
image:
repository: ghcr.io/pluralsh/ferrotunnel-client
tag: master
token: ""
ca: ""
cert: ""
key: ""
18 changes: 18 additions & 0 deletions charts/deployment-operator/values.yaml.liquid
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,24 @@ agentk:
tag: {{ configuration.agentkTag }}
{% endif %}

{% if configuration.tunnelServer and configuration.tunnelToken and configuration.tunnelCa and configuration.tunnelCert and configuration.tunnelKey %}
ferrotunnel:
enabled: true
server: "{{ configuration.tunnelServer }}"
token: "{{ configuration.tunnelToken }}"
ca: "{{ configuration.tunnelCa }}"
cert: "{{ configuration.tunnelCert }}"
key: "{{ configuration.tunnelKey }}"
{% if configuration.ferrotunnelTag %}
image:
tag: {{ configuration.ferrotunnelTag }}
{% endif %}
{% elsif configuration.ferrotunnelTag %}
ferrotunnel:
image:
tag: {{ configuration.ferrotunnelTag }}
{% endif %}

{% if configuration.replicas %}
replicaCount: {{ configuration.replicas }}
{% endif %}
Expand Down
Loading