mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 19:26:38 +00:00
Merge pull request #3302 from Infisical/daniel/helm-fix
feat(k8s): preserve helm charts and streamline release process
This commit is contained in:
@@ -0,0 +1,27 @@
|
|||||||
|
name: Release K8 Operator Helm Chart
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
release-helm:
|
||||||
|
name: Release Helm Chart
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
|
- name: Install Helm
|
||||||
|
uses: azure/setup-helm@v3
|
||||||
|
with:
|
||||||
|
version: v3.10.0
|
||||||
|
|
||||||
|
- name: Install python
|
||||||
|
uses: actions/setup-python@v4
|
||||||
|
|
||||||
|
- name: Install Cloudsmith CLI
|
||||||
|
run: pip install --upgrade cloudsmith-cli
|
||||||
|
|
||||||
|
- name: Build and push helm package to CloudSmith
|
||||||
|
run: cd helm-charts && sh upload-k8s-operator-cloudsmith.sh
|
||||||
|
env:
|
||||||
|
CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }}
|
||||||
@@ -1,52 +1,103 @@
|
|||||||
name: Release image + Helm chart K8s Operator
|
name: Release K8 Operator Docker Image
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
tags:
|
tags:
|
||||||
- "infisical-k8-operator/v*.*.*"
|
- "infisical-k8-operator/v*.*.*"
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
release:
|
release-image:
|
||||||
runs-on: ubuntu-latest
|
name: Generate Helm Chart PR
|
||||||
steps:
|
runs-on: ubuntu-latest
|
||||||
- name: Extract version from tag
|
outputs:
|
||||||
id: extract_version
|
pr_number: ${{ steps.create-pr.outputs.pull-request-number }}
|
||||||
run: echo "::set-output name=version::${GITHUB_REF_NAME#infisical-k8-operator/}"
|
steps:
|
||||||
- uses: actions/checkout@v2
|
- name: Extract version from tag
|
||||||
|
id: extract_version
|
||||||
|
run: echo "::set-output name=version::${GITHUB_REF_NAME#infisical-k8-operator/}"
|
||||||
|
|
||||||
- name: 🔧 Set up QEMU
|
- name: Checkout code
|
||||||
uses: docker/setup-qemu-action@v1
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
- name: 🔧 Set up Docker Buildx
|
# Dependency for helm generation
|
||||||
uses: docker/setup-buildx-action@v1
|
- name: Install Helm
|
||||||
|
uses: azure/setup-helm@v3
|
||||||
|
with:
|
||||||
|
version: v3.10.0
|
||||||
|
|
||||||
- name: 🐋 Login to Docker Hub
|
# Dependency for helm generation
|
||||||
uses: docker/login-action@v1
|
- name: Install Go
|
||||||
with:
|
uses: actions/setup-go@v4
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
with:
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
go-version: 1.21
|
||||||
|
|
||||||
- name: Build and push
|
# Install binaries for helm generation
|
||||||
id: docker_build
|
- name: Install dependencies
|
||||||
uses: docker/build-push-action@v2
|
working-directory: k8-operator
|
||||||
with:
|
run: |
|
||||||
context: k8-operator
|
make helmify
|
||||||
push: true
|
make kustomize
|
||||||
platforms: linux/amd64,linux/arm64
|
make controller-gen
|
||||||
tags: |
|
|
||||||
infisical/kubernetes-operator:latest
|
|
||||||
infisical/kubernetes-operator:${{ steps.extract_version.outputs.version }}
|
|
||||||
|
|
||||||
- name: Checkout
|
- name: Generate Helm Chart
|
||||||
uses: actions/checkout@v2
|
working-directory: k8-operator
|
||||||
- name: Install Helm
|
run: make helm
|
||||||
uses: azure/setup-helm@v3
|
|
||||||
with:
|
- name: Update Helm Chart Version
|
||||||
version: v3.10.0
|
run: ./k8-operator/scripts/update-version.sh ${{ steps.extract_version.outputs.version }}
|
||||||
- name: Install python
|
|
||||||
uses: actions/setup-python@v4
|
- name: Debug - Check file changes
|
||||||
- name: Install Cloudsmith CLI
|
run: |
|
||||||
run: pip install --upgrade cloudsmith-cli
|
echo "Current git status:"
|
||||||
- name: Build and push helm package to Cloudsmith
|
git status
|
||||||
run: cd helm-charts && sh upload-k8s-operator-cloudsmith.sh
|
echo ""
|
||||||
env:
|
echo "Modified files:"
|
||||||
CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }}
|
git diff --name-only
|
||||||
|
|
||||||
|
# If there is no diff, exit with error. Version should always be changed, so if there is no diff, something is wrong and we should exit.
|
||||||
|
if [ -z "$(git diff --name-only)" ]; then
|
||||||
|
echo "No helm changes or version changes. Invalid release detected, Exiting."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
- name: Create Helm Chart PR
|
||||||
|
id: create-pr
|
||||||
|
uses: peter-evans/create-pull-request@v5
|
||||||
|
with:
|
||||||
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
commit-message: "Update Helm chart to version ${{ steps.extract_version.outputs.version }}"
|
||||||
|
committer: GitHub <[email protected]>
|
||||||
|
author: ${{ github.actor }} <${{ github.actor }}@users.noreply.github.com>
|
||||||
|
branch: helm-update-${{ steps.extract_version.outputs.version }}
|
||||||
|
delete-branch: true
|
||||||
|
title: "Update Helm chart to version ${{ steps.extract_version.outputs.version }}"
|
||||||
|
body: |
|
||||||
|
This PR updates the Helm chart to version `${{ steps.extract_version.outputs.version }}`.
|
||||||
|
Additionally the helm chart has been updated to match the latest operator code changes.
|
||||||
|
|
||||||
|
Associated Release Workflow: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}
|
||||||
|
|
||||||
|
Once you have approved this PR, you can trigger the helm release workflow manually.
|
||||||
|
base: main
|
||||||
|
|
||||||
|
- name: 🔧 Set up QEMU
|
||||||
|
uses: docker/setup-qemu-action@v1
|
||||||
|
|
||||||
|
- name: 🔧 Set up Docker Buildx
|
||||||
|
uses: docker/setup-buildx-action@v1
|
||||||
|
|
||||||
|
- name: 🐋 Login to Docker Hub
|
||||||
|
uses: docker/login-action@v1
|
||||||
|
with:
|
||||||
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||||
|
|
||||||
|
- name: Build and push
|
||||||
|
id: docker_build
|
||||||
|
uses: docker/build-push-action@v2
|
||||||
|
with:
|
||||||
|
context: k8-operator
|
||||||
|
push: true
|
||||||
|
platforms: linux/amd64,linux/arm64
|
||||||
|
tags: |
|
||||||
|
infisical/kubernetes-operator:latest
|
||||||
|
infisical/kubernetes-operator:${{ steps.extract_version.outputs.version }}
|
||||||
|
|||||||
@@ -88,4 +88,4 @@ spec:
|
|||||||
serviceAccountName: {{ include "secrets-operator.fullname" . }}-controller-manager
|
serviceAccountName: {{ include "secrets-operator.fullname" . }}-controller-manager
|
||||||
terminationGracePeriodSeconds: 10
|
terminationGracePeriodSeconds: 10
|
||||||
nodeSelector: {{ toYaml .Values.controllerManager.nodeSelector | nindent 8 }}
|
nodeSelector: {{ toYaml .Values.controllerManager.nodeSelector | nindent 8 }}
|
||||||
tolerations: {{ toYaml .Values.controllerManager.tolerations | nindent 8 }}
|
tolerations: {{ toYaml .Values.controllerManager.tolerations | nindent 8 }}
|
||||||
|
|||||||
@@ -309,4 +309,4 @@ status:
|
|||||||
plural: ""
|
plural: ""
|
||||||
conditions: []
|
conditions: []
|
||||||
storedVersions: []
|
storedVersions: []
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -266,4 +266,4 @@ status:
|
|||||||
plural: ""
|
plural: ""
|
||||||
conditions: []
|
conditions: []
|
||||||
storedVersions: []
|
storedVersions: []
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -504,5 +504,4 @@ status:
|
|||||||
plural: ""
|
plural: ""
|
||||||
conditions: []
|
conditions: []
|
||||||
storedVersions: []
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
|
||||||
|
|||||||
@@ -56,4 +56,4 @@ roleRef:
|
|||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: '{{ include "secrets-operator.fullname" . }}-controller-manager'
|
name: '{{ include "secrets-operator.fullname" . }}-controller-manager'
|
||||||
namespace: '{{ .Release.Namespace }}'
|
namespace: '{{ .Release.Namespace }}'
|
||||||
|
|||||||
@@ -53,6 +53,15 @@ rules:
|
|||||||
- list
|
- list
|
||||||
- update
|
- update
|
||||||
- watch
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- secrets.infisical.com
|
- secrets.infisical.com
|
||||||
resources:
|
resources:
|
||||||
@@ -159,4 +168,4 @@ roleRef:
|
|||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: '{{ include "secrets-operator.fullname" . }}-controller-manager'
|
name: '{{ include "secrets-operator.fullname" . }}-controller-manager'
|
||||||
namespace: '{{ .Release.Namespace }}'
|
namespace: '{{ .Release.Namespace }}'
|
||||||
|
|||||||
@@ -13,4 +13,5 @@ rules:
|
|||||||
- /metrics
|
- /metrics
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
{{- end }}
|
|
||||||
|
{{- end }}
|
||||||
|
|||||||
@@ -14,4 +14,4 @@ spec:
|
|||||||
control-plane: controller-manager
|
control-plane: controller-manager
|
||||||
{{- include "secrets-operator.selectorLabels" . | nindent 4 }}
|
{{- include "secrets-operator.selectorLabels" . | nindent 4 }}
|
||||||
ports:
|
ports:
|
||||||
{{- .Values.metricsService.ports | toYaml | nindent 2 }}
|
{{- .Values.metricsService.ports | toYaml | nindent 2 }}
|
||||||
|
|||||||
@@ -39,4 +39,5 @@ subjects:
|
|||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: '{{ include "secrets-operator.fullname" . }}-controller-manager'
|
name: '{{ include "secrets-operator.fullname" . }}-controller-manager'
|
||||||
namespace: '{{ .Release.Namespace }}'
|
namespace: '{{ .Release.Namespace }}'
|
||||||
{{- end }}
|
|
||||||
|
{{- end }}
|
||||||
|
|||||||
@@ -8,4 +8,4 @@ metadata:
|
|||||||
app.kubernetes.io/part-of: k8-operator
|
app.kubernetes.io/part-of: k8-operator
|
||||||
{{- include "secrets-operator.labels" . | nindent 4 }}
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
annotations:
|
annotations:
|
||||||
{{- toYaml .Values.controllerManager.serviceAccount.annotations | nindent 4 }}
|
{{- toYaml .Values.controllerManager.serviceAccount.annotations | nindent 4 }}
|
||||||
|
|||||||
@@ -1,15 +1,15 @@
|
|||||||
controllerManager:
|
controllerManager:
|
||||||
kubeRbacProxy:
|
kubeRbacProxy:
|
||||||
args:
|
args:
|
||||||
- --secure-listen-address=0.0.0.0:8443
|
- --secure-listen-address=0.0.0.0:8443
|
||||||
- --upstream=http://127.0.0.1:8080/
|
- --upstream=http://127.0.0.1:8080/
|
||||||
- --logtostderr=true
|
- --logtostderr=true
|
||||||
- --v=0
|
- --v=0
|
||||||
containerSecurityContext:
|
containerSecurityContext:
|
||||||
allowPrivilegeEscalation: false
|
allowPrivilegeEscalation: false
|
||||||
capabilities:
|
capabilities:
|
||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
image:
|
image:
|
||||||
repository: gcr.io/kubebuilder/kube-rbac-proxy
|
repository: gcr.io/kubebuilder/kube-rbac-proxy
|
||||||
tag: v0.15.0
|
tag: v0.15.0
|
||||||
@@ -22,17 +22,17 @@ controllerManager:
|
|||||||
memory: 64Mi
|
memory: 64Mi
|
||||||
manager:
|
manager:
|
||||||
args:
|
args:
|
||||||
- --health-probe-bind-address=:8081
|
- --health-probe-bind-address=:8081
|
||||||
- --metrics-bind-address=127.0.0.1:8080
|
- --metrics-bind-address=127.0.0.1:8080
|
||||||
- --leader-elect
|
- --leader-elect
|
||||||
containerSecurityContext:
|
containerSecurityContext:
|
||||||
allowPrivilegeEscalation: false
|
allowPrivilegeEscalation: false
|
||||||
capabilities:
|
capabilities:
|
||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
image:
|
image:
|
||||||
repository: infisical/kubernetes-operator
|
repository: infisical/kubernetes-operator
|
||||||
tag: v0.8.15
|
tag: <helm-pr-will-update-this-automatically>
|
||||||
resources:
|
resources:
|
||||||
limits:
|
limits:
|
||||||
cpu: 500m
|
cpu: 500m
|
||||||
@@ -45,14 +45,14 @@ controllerManager:
|
|||||||
annotations: {}
|
annotations: {}
|
||||||
nodeSelector: {}
|
nodeSelector: {}
|
||||||
tolerations: []
|
tolerations: []
|
||||||
|
metricsService:
|
||||||
|
ports:
|
||||||
|
- name: https
|
||||||
|
port: 8443
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: https
|
||||||
|
type: ClusterIP
|
||||||
kubernetesClusterDomain: cluster.local
|
kubernetesClusterDomain: cluster.local
|
||||||
scopedNamespace: ""
|
scopedNamespace: ""
|
||||||
scopedRBAC: false
|
scopedRBAC: false
|
||||||
installCRDs: true
|
installCRDs: true
|
||||||
metricsService:
|
|
||||||
ports:
|
|
||||||
- name: https
|
|
||||||
port: 8443
|
|
||||||
protocol: TCP
|
|
||||||
targetPort: https
|
|
||||||
type: ClusterIP
|
|
||||||
|
|||||||
@@ -48,9 +48,12 @@ helmify: $(HELMIFY) ## Download helmify locally if necessary.
|
|||||||
$(HELMIFY): $(LOCALBIN)
|
$(HELMIFY): $(LOCALBIN)
|
||||||
test -s $(LOCALBIN)/helmify || GOBIN=$(LOCALBIN) go install github.com/arttor/helmify/cmd/helmify@latest
|
test -s $(LOCALBIN)/helmify || GOBIN=$(LOCALBIN) go install github.com/arttor/helmify/cmd/helmify@latest
|
||||||
|
|
||||||
helm: manifests kustomize helmify
|
legacy-helm: manifests kustomize helmify
|
||||||
$(KUSTOMIZE) build config/default | $(HELMIFY) ../helm-charts/secrets-operator
|
$(KUSTOMIZE) build config/default | $(HELMIFY) ../helm-charts/secrets-operator
|
||||||
|
|
||||||
|
helm: manifests kustomize helmify
|
||||||
|
./scripts/generate-helm.sh
|
||||||
|
|
||||||
## Yaml for Kubectl
|
## Yaml for Kubectl
|
||||||
kubectl-install: manifests kustomize
|
kubectl-install: manifests kustomize
|
||||||
mkdir -p kubectl-install
|
mkdir -p kubectl-install
|
||||||
|
|||||||
Executable
+332
@@ -0,0 +1,332 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" &> /dev/null && pwd)
|
||||||
|
PROJECT_ROOT=$(cd "${SCRIPT_DIR}/.." && pwd)
|
||||||
|
HELM_DIR="${PROJECT_ROOT}/../helm-charts/secrets-operator"
|
||||||
|
LOCALBIN="${PROJECT_ROOT}/bin"
|
||||||
|
KUSTOMIZE="${LOCALBIN}/kustomize"
|
||||||
|
HELMIFY="${LOCALBIN}/helmify"
|
||||||
|
|
||||||
|
|
||||||
|
cd "${PROJECT_ROOT}"
|
||||||
|
# first run the regular helm target to generate base templates
|
||||||
|
"${KUSTOMIZE}" build config/default | "${HELMIFY}" "${HELM_DIR}"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# ? NOTE: Processes all files that end with crd.yaml (so only actual CRDs)
|
||||||
|
for crd_file in "${HELM_DIR}"/templates/*crd.yaml; do
|
||||||
|
# skip if file doesn't exist (pattern doesn't match)
|
||||||
|
[ -e "$crd_file" ] || continue
|
||||||
|
|
||||||
|
echo "Processing CRD file: ${crd_file}"
|
||||||
|
|
||||||
|
cp "$crd_file" "$crd_file.bkp"
|
||||||
|
|
||||||
|
# if we ever need to run conditional logic based on the CRD kind, we can use this
|
||||||
|
# CRD_KIND=$(grep -E "kind: [a-zA-Z]+" "$crd_file" | head -n1 | awk '{print $2}')
|
||||||
|
# echo "Found CRD kind: ${CRD_KIND}"
|
||||||
|
|
||||||
|
# create a new file with the conditional statement, then append the entire original content
|
||||||
|
echo "{{- if .Values.installCRDs }}" > "$crd_file.new"
|
||||||
|
cat "$crd_file.bkp" >> "$crd_file.new"
|
||||||
|
|
||||||
|
# make sure the file ends with a newline before adding the end tag (otherwise it might get messed up and end up on the same line as the last line)
|
||||||
|
# check if file already ends with a newline
|
||||||
|
if [ "$(tail -c1 "$crd_file.new" | wc -l)" -eq 0 ]; then
|
||||||
|
# File doesn't end with a newline, add one
|
||||||
|
echo "" >> "$crd_file.new"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# add the end tag on a new line
|
||||||
|
echo "{{- end }}" >> "$crd_file.new"
|
||||||
|
|
||||||
|
# replace the original file with the new one
|
||||||
|
mv "$crd_file.new" "$crd_file"
|
||||||
|
|
||||||
|
# clean up backup
|
||||||
|
rm "$crd_file.bkp"
|
||||||
|
|
||||||
|
echo "Completed processing for: ${crd_file}"
|
||||||
|
done
|
||||||
|
|
||||||
|
# ? NOTE: Processes only the manager-rbac.yaml file
|
||||||
|
if [ -f "${HELM_DIR}/templates/manager-rbac.yaml" ]; then
|
||||||
|
echo "Processing manager-rbac.yaml file specifically"
|
||||||
|
|
||||||
|
|
||||||
|
cp "${HELM_DIR}/templates/manager-rbac.yaml" "${HELM_DIR}/templates/manager-rbac.yaml.bkp"
|
||||||
|
|
||||||
|
# extract the rules section from the original file
|
||||||
|
rules_section=$(sed -n '/^rules:/,/^---/p' "${HELM_DIR}/templates/manager-rbac.yaml.bkp" | sed '$d')
|
||||||
|
# extract the original label lines
|
||||||
|
original_labels=$(sed -n '/^ labels:/,/^roleRef:/p' "${HELM_DIR}/templates/manager-rbac.yaml.bkp" | grep "app.kubernetes.io")
|
||||||
|
|
||||||
|
# create a new file from scratch with exactly what we want
|
||||||
|
{
|
||||||
|
# first section: Role/ClusterRole
|
||||||
|
echo "apiVersion: rbac.authorization.k8s.io/v1"
|
||||||
|
echo "{{- if and .Values.scopedNamespace .Values.scopedRBAC }}"
|
||||||
|
echo "kind: Role"
|
||||||
|
echo "{{- else }}"
|
||||||
|
echo "kind: ClusterRole"
|
||||||
|
echo "{{- end }}"
|
||||||
|
echo "metadata:"
|
||||||
|
echo " name: {{ include \"secrets-operator.fullname\" . }}-manager-role"
|
||||||
|
echo " {{- if and .Values.scopedNamespace .Values.scopedRBAC }}"
|
||||||
|
echo " namespace: {{ .Values.scopedNamespace | quote }}"
|
||||||
|
echo " {{- end }}"
|
||||||
|
echo " labels:"
|
||||||
|
echo " {{- include \"secrets-operator.labels\" . | nindent 4 }}"
|
||||||
|
|
||||||
|
# add the existing rules section from helm-generated file
|
||||||
|
echo "$rules_section"
|
||||||
|
|
||||||
|
# second section: RoleBinding/ClusterRoleBinding
|
||||||
|
echo "---"
|
||||||
|
echo "apiVersion: rbac.authorization.k8s.io/v1"
|
||||||
|
echo "{{- if and .Values.scopedNamespace .Values.scopedRBAC }}"
|
||||||
|
echo "kind: RoleBinding"
|
||||||
|
echo "{{- else }}"
|
||||||
|
echo "kind: ClusterRoleBinding"
|
||||||
|
echo "{{- end }}"
|
||||||
|
echo "metadata:"
|
||||||
|
echo " name: {{ include \"secrets-operator.fullname\" . }}-manager-rolebinding"
|
||||||
|
echo " {{- if and .Values.scopedNamespace .Values.scopedRBAC }}"
|
||||||
|
echo " namespace: {{ .Values.scopedNamespace | quote }}"
|
||||||
|
echo " {{- end }}"
|
||||||
|
echo " labels:"
|
||||||
|
echo "$original_labels"
|
||||||
|
echo " {{- include \"secrets-operator.labels\" . | nindent 4 }}"
|
||||||
|
|
||||||
|
# add the roleRef section with custom logic
|
||||||
|
echo "roleRef:"
|
||||||
|
echo " apiGroup: rbac.authorization.k8s.io"
|
||||||
|
echo " {{- if and .Values.scopedNamespace .Values.scopedRBAC }}"
|
||||||
|
echo " kind: Role"
|
||||||
|
echo " {{- else }}"
|
||||||
|
echo " kind: ClusterRole"
|
||||||
|
echo " {{- end }}"
|
||||||
|
echo " name: '{{ include \"secrets-operator.fullname\" . }}-manager-role'"
|
||||||
|
|
||||||
|
# add the subjects section
|
||||||
|
sed -n '/^subjects:/,$ p' "${HELM_DIR}/templates/manager-rbac.yaml.bkp"
|
||||||
|
} > "${HELM_DIR}/templates/manager-rbac.yaml.new"
|
||||||
|
|
||||||
|
mv "${HELM_DIR}/templates/manager-rbac.yaml.new" "${HELM_DIR}/templates/manager-rbac.yaml"
|
||||||
|
rm "${HELM_DIR}/templates/manager-rbac.yaml.bkp"
|
||||||
|
|
||||||
|
echo "Completed processing for manager-rbac.yaml with both role conditions and metadata applied"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ? NOTE(Daniel): Processes proxy-rbac.yaml and metrics-reader-rbac.yaml
|
||||||
|
for rbac_file in "${HELM_DIR}/templates/proxy-rbac.yaml" "${HELM_DIR}/templates/metrics-reader-rbac.yaml"; do
|
||||||
|
if [ -f "$rbac_file" ]; then
|
||||||
|
echo "Adding scopedNamespace condition to $(basename "$rbac_file")"
|
||||||
|
|
||||||
|
{
|
||||||
|
echo "{{- if not .Values.scopedNamespace }}"
|
||||||
|
cat "$rbac_file"
|
||||||
|
echo ""
|
||||||
|
echo "{{- end }}"
|
||||||
|
} > "$rbac_file.new"
|
||||||
|
|
||||||
|
mv "$rbac_file.new" "$rbac_file"
|
||||||
|
|
||||||
|
echo "Completed processing for $(basename "$rbac_file")"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
|
||||||
|
# ? NOTE(Daniel): Processes metrics-service.yaml
|
||||||
|
if [ -f "${HELM_DIR}/templates/metrics-service.yaml" ]; then
|
||||||
|
echo "Processing metrics-service.yaml file specifically"
|
||||||
|
|
||||||
|
metrics_file="${HELM_DIR}/templates/metrics-service.yaml"
|
||||||
|
touch "${metrics_file}.new"
|
||||||
|
|
||||||
|
while IFS= read -r line; do
|
||||||
|
if [[ "$line" == *"{{- include \"secrets-operator.selectorLabels\" . | nindent 4 }}"* ]]; then
|
||||||
|
# keep original indentation for the selector labels line
|
||||||
|
echo " {{- include \"secrets-operator.selectorLabels\" . | nindent 4 }}" >> "${metrics_file}.new"
|
||||||
|
elif [[ "$line" == *"{{- .Values.metricsService.ports | toYaml | nindent 2 }}"* ]]; then
|
||||||
|
# fix indentation for the ports line - use less indentation here
|
||||||
|
echo " {{- .Values.metricsService.ports | toYaml | nindent 2 }}" >> "${metrics_file}.new"
|
||||||
|
else
|
||||||
|
echo "$line" >> "${metrics_file}.new"
|
||||||
|
fi
|
||||||
|
done < "${metrics_file}"
|
||||||
|
|
||||||
|
mv "${metrics_file}.new" "${metrics_file}"
|
||||||
|
echo "Completed processing for metrics_service.yaml"
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# ? NOTE(Daniel): Processes deployment.yaml
|
||||||
|
if [ -f "${HELM_DIR}/templates/deployment.yaml" ]; then
|
||||||
|
echo "Processing deployment.yaml file"
|
||||||
|
|
||||||
|
touch "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
|
||||||
|
securityContext_replaced=0
|
||||||
|
in_first_securityContext=0
|
||||||
|
first_securityContext_found=0
|
||||||
|
|
||||||
|
# process the file line by line
|
||||||
|
while IFS= read -r line; do
|
||||||
|
# check if this is the first securityContext line (for kube-rbac-proxy)
|
||||||
|
if [[ "$line" =~ securityContext.*Values.controllerManager.kubeRbacProxy ]] && [ "$first_securityContext_found" -eq 0 ]; then
|
||||||
|
echo "$line" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
first_securityContext_found=1
|
||||||
|
in_first_securityContext=1
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
# check if this is the args line after the first securityContext
|
||||||
|
if [ "$in_first_securityContext" -eq 1 ] && [[ "$line" =~ args: ]]; then
|
||||||
|
# Add our custom args section with conditional logic
|
||||||
|
echo " - args:" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
echo " {{- toYaml .Values.controllerManager.manager.args | nindent 8 }}" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
echo " {{- if and .Values.scopedNamespace .Values.scopedRBAC }}" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
echo " - --namespace={{ .Values.scopedNamespace }}" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
echo " {{- end }}" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
in_first_securityContext=0
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
# check if this is the problematic pod securityContext line
|
||||||
|
if [[ "$line" =~ securityContext.*Values.controllerManager.podSecurityContext ]] && [ "$securityContext_replaced" -eq 0 ]; then
|
||||||
|
# Replace with our custom securityContext
|
||||||
|
echo " securityContext:" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
echo " runAsNonRoot: true" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
securityContext_replaced=1
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
# skip the line if it's just the trailing part of the replacement
|
||||||
|
if [[ "$securityContext_replaced" -eq 1 ]] && [[ "$line" =~ ^[[:space:]]*[0-9]+[[:space:]]*\}\} ]]; then
|
||||||
|
# this is the trailing part of the template expression, skip it
|
||||||
|
securityContext_replaced=0
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
# skip the simplified args line that replaced our custom one
|
||||||
|
if [[ "$line" =~ args:.*Values.controllerManager.manager.args ]]; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "$line" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
done < "${HELM_DIR}/templates/deployment.yaml"
|
||||||
|
|
||||||
|
echo " nodeSelector: {{ toYaml .Values.controllerManager.nodeSelector | nindent 8 }}" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
echo " tolerations: {{ toYaml .Values.controllerManager.tolerations | nindent 8 }}" >> "${HELM_DIR}/templates/deployment.yaml.new"
|
||||||
|
|
||||||
|
mv "${HELM_DIR}/templates/deployment.yaml.new" "${HELM_DIR}/templates/deployment.yaml"
|
||||||
|
echo "Completed processing for deployment.yaml"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ? NOTE(Daniel): Processes values.yaml
|
||||||
|
if [ -f "${HELM_DIR}/values.yaml" ]; then
|
||||||
|
echo "Processing values.yaml file"
|
||||||
|
|
||||||
|
# Create a temporary file
|
||||||
|
touch "${HELM_DIR}/values.yaml.new"
|
||||||
|
|
||||||
|
# Flag to track sections
|
||||||
|
in_resources_section=0
|
||||||
|
in_service_account=0
|
||||||
|
|
||||||
|
previous_line=""
|
||||||
|
# Process the file line by line
|
||||||
|
while IFS= read -r line; do
|
||||||
|
|
||||||
|
# Check if previous line includes infisical/kubernetes-operator and this line includes tag:
|
||||||
|
if [[ "$previous_line" =~ infisical/kubernetes-operator ]] && [[ "$line" =~ ^[[:space:]]*tag: ]]; then
|
||||||
|
# Get the indentation
|
||||||
|
indent=$(echo "$line" | sed 's/\(^[[:space:]]*\).*/\1/')
|
||||||
|
# Replace with our custom tag
|
||||||
|
echo "${indent}tag: <helm-pr-will-update-this-automatically>" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
if [[ "$line" =~ resources: ]]; then
|
||||||
|
in_resources_section=1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$line" =~ podSecurityContext: ]]; then
|
||||||
|
# skip this line and continue to the next line
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$line" =~ runAsNonRoot: ]] && [ "$in_resources_section" -eq 1 ]; then
|
||||||
|
# also skip this line and continue to the next line
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$line" =~ ^[[:space:]]*serviceAccount: ]]; then
|
||||||
|
# set the flag to 1 so we can continue to print the associated lines later
|
||||||
|
in_service_account=1
|
||||||
|
# print the current line
|
||||||
|
echo "$line" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
# process annotations under serviceAccount (only if in_service_account is true)
|
||||||
|
if [ "$in_service_account" -eq 1 ]; then
|
||||||
|
# Print the current line (annotations)
|
||||||
|
echo "$line" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
|
||||||
|
# if we've processed the annotations, add our new fields
|
||||||
|
if [[ "$line" =~ annotations: ]]; then
|
||||||
|
# get the base indentation level (of serviceAccount:)
|
||||||
|
base_indent=$(echo "$line" | sed 's/\(^[[:space:]]*\).*/\1/')
|
||||||
|
base_indent=${base_indent%??} # Remove two spaces to get to parent level
|
||||||
|
|
||||||
|
# add nodeSelector and tolerations at the same level as serviceAccount
|
||||||
|
echo "${base_indent}nodeSelector: {}" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
echo "${base_indent}tolerations: []" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# exit serviceAccount section when we hit the next top-level item
|
||||||
|
if [[ "$line" =~ ^[[:space:]]{2}[a-zA-Z] ]] && ! [[ "$line" =~ annotations: ]]; then
|
||||||
|
in_service_account=0
|
||||||
|
fi
|
||||||
|
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
# if we reach this point, we'll exit the resources section, this is the next top-level item
|
||||||
|
if [ "$in_resources_section" -eq 1 ] && [[ "$line" =~ ^[[:space:]]{2}[a-zA-Z] ]]; then
|
||||||
|
in_resources_section=0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# output the line unchanged
|
||||||
|
echo "$line" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
previous_line="$line"
|
||||||
|
done < "${HELM_DIR}/values.yaml"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# hacky, just append the kubernetesClusterDomain fields at the end of the file
|
||||||
|
if [[ "$OSTYPE" == "darwin"* ]]; then
|
||||||
|
# macOS version
|
||||||
|
sed -i '' '/kubernetesClusterDomain: /d' "${HELM_DIR}/values.yaml.new"
|
||||||
|
else
|
||||||
|
# Linux version
|
||||||
|
sed -i '/kubernetesClusterDomain: /d' "${HELM_DIR}/values.yaml.new"
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "kubernetesClusterDomain: cluster.local" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
echo "scopedNamespace: \"\"" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
echo "scopedRBAC: false" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
echo "installCRDs: true" >> "${HELM_DIR}/values.yaml.new"
|
||||||
|
|
||||||
|
# replace the original file with the new one
|
||||||
|
mv "${HELM_DIR}/values.yaml.new" "${HELM_DIR}/values.yaml"
|
||||||
|
|
||||||
|
echo "Completed processing for values.yaml"
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Helm chart generation complete with custom templating applied."
|
||||||
Executable
+37
@@ -0,0 +1,37 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" &> /dev/null && pwd)
|
||||||
|
PATH_TO_HELM_CHART="${SCRIPT_DIR}/../../helm-charts/secrets-operator"
|
||||||
|
|
||||||
|
VERSION=$1
|
||||||
|
VERSION_WITHOUT_V=$(echo "$VERSION" | sed 's/^v//') # needed to validate semver
|
||||||
|
|
||||||
|
|
||||||
|
if [ -z "$VERSION" ]; then
|
||||||
|
echo "Usage: $0 <version>"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
if ! [[ "$VERSION_WITHOUT_V" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||||
|
echo "Error: Version must follow semantic versioning (e.g. 0.0.1)"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if ! [[ "$VERSION" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||||
|
echo "Error: Version must start with 'v' (e.g. v0.0.1)"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# For Linux vs macOS sed compatibility
|
||||||
|
if [[ "$OSTYPE" == "darwin"* ]]; then
|
||||||
|
# macOS version
|
||||||
|
sed -i '' -e '/repository: infisical\/kubernetes-operator/{n;s/tag: .*/tag: '"$VERSION"'/;}' "${PATH_TO_HELM_CHART}/values.yaml"
|
||||||
|
sed -i '' 's/appVersion: .*/appVersion: "'"$VERSION"'"/g' "${PATH_TO_HELM_CHART}/Chart.yaml"
|
||||||
|
sed -i '' 's/version: .*/version: '"$VERSION"'/g' "${PATH_TO_HELM_CHART}/Chart.yaml"
|
||||||
|
else
|
||||||
|
# Linux version
|
||||||
|
sed -i -e '/repository: infisical\/kubernetes-operator/{n;s/tag: .*/tag: '"$VERSION"'/;}' "${PATH_TO_HELM_CHART}/values.yaml"
|
||||||
|
sed -i 's/appVersion: .*/appVersion: "'"$VERSION"'"/g' "${PATH_TO_HELM_CHART}/Chart.yaml"
|
||||||
|
sed -i 's/version: .*/version: '"$VERSION"'/g' "${PATH_TO_HELM_CHART}/Chart.yaml"
|
||||||
|
fi
|
||||||
Reference in New Issue
Block a user