-
Notifications
You must be signed in to change notification settings - Fork 73
Add support for Calico, use RBAC and secrets encryption. #283
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,3 +4,4 @@ _artifact/ | |
| *.pem | ||
| *.csr | ||
| *.kubeconfig | ||
| manifests/calico/tigera-operator.yaml | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -19,6 +19,6 @@ exec $(dirname $0)/nsenter.sh kube-apiserver \ | |
| --service-account-signing-key-file=$XDG_CONFIG_HOME/usernetes/master/service-account-key.pem \ | ||
| --advertise-address=$(cat $XDG_RUNTIME_DIR/usernetes/parent_ip) \ | ||
| --allow-privileged \ | ||
| --authorization-mode=Node,RBAC \ | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Could you split and squash the commits so that one commit has one topic? Probably, this PR should have the following three commits:
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. How should I handle
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Just make commit 3 depend on commit 1 and 2? |
||
| --encryption-provider-config=$XDG_CONFIG_HOME/usernetes/master/secrets-encryption.yml \ | ||
| $@ | ||
|
|
||
| # TODO: enable --authorization-mode=Node,RBAC \ | ||
| Original file line number | Diff line number | Diff line change | ||
|---|---|---|---|---|
|
|
@@ -51,7 +51,7 @@ function usage() { | |||
| echo | ||||
| echo " --start=UNIT Enable and start the specified target after the installation, e.g. \"u7s.target\". Set to an empty to disable autostart. (Default: \"$start\")" | ||||
| echo " --cri=RUNTIME Specify CRI runtime, \"containerd\" or \"crio\". (Default: \"$cri\")" | ||||
| echo ' --cni=RUNTIME Specify CNI, an empty string (none) or "flannel". (Default: none)' | ||||
| echo ' --cni=RUNTIME Specify CNI, an empty string (none), \"calico\" or "flannel". (Default: none)' | ||||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Can we test calico in CI ? usernetes/.github/workflows/main.yaml Line 24 in 58df6ea
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We should be able to, I have never used Github CI but I can look into it.
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Could you update |
||||
| echo " -p, --publish=PORT Publish ports in RootlessKit's network namespace, e.g. \"0.0.0.0:10250:10250/tcp\". Can be specified multiple times. (Default: \"${publish_default}\")" | ||||
| echo " --cidr=CIDR Specify CIDR of RootlessKit's network namespace, e.g. \"10.0.100.0/24\". (Default: \"$cidr\")" | ||||
| echo | ||||
|
|
@@ -107,7 +107,7 @@ while true; do | |||
| --cni) | ||||
| cni="$2" | ||||
| case "$cni" in | ||||
| "" | "flannel") ;; | ||||
| "" | "flannel" | "calico") ;; | ||||
|
|
||||
| *) | ||||
| ERROR "Unknown CNI \"$cni\". Supported values: \"\" (default) \"flannel\" ." | ||||
|
|
@@ -429,6 +429,20 @@ EOF | |||
| fi | ||||
| fi | ||||
|
|
||||
| # Need to enable calico before starting rootlesskit | ||||
| if [ "$cni" = "calico" ]; then | ||||
| cat <<EOF >>${config_dir}/usernetes/env | ||||
| U7S_CALICO=1 | ||||
| EOF | ||||
| fi | ||||
|
|
||||
| ### Secret encryption | ||||
| if [ ! -f ${config_dir}/usernetes/master/secrets-encryption.yaml.template ]; then | ||||
| INFO "Enabling secrets encryption" | ||||
| export ENCRYPTION_SECRET=$(cat /dev/urandom | head -c 32 | base64 -w 0) | ||||
| (envsubst '$ENCRYPTION_SECRET' < manifests/secrets-encryption.yaml.template) > ${config_dir}/usernetes/master/secrets-encryption.yml | ||||
| fi | ||||
|
|
||||
| ### Finish installation | ||||
| systemctl --user daemon-reload | ||||
| if [ -z $start ]; then | ||||
|
|
@@ -447,6 +461,51 @@ if systemctl --user -q is-active u7s-master.target; then | |||
| PATH="${base}/bin:$PATH" | ||||
| KUBECONFIG="${config_dir}/usernetes/master/admin-localhost.kubeconfig" | ||||
| export PATH KUBECONFIG | ||||
| INFO "Granting all permissions to kubectl" | ||||
| cat <<EOF | kubectl apply -f - | ||||
| apiVersion: rbac.authorization.k8s.io/v1 | ||||
| kind: ClusterRole | ||||
| metadata: | ||||
| annotations: | ||||
| rbac.authorization.kubernetes.io/autoupdate: "true" | ||||
| labels: | ||||
| kubernetes.io/bootstrapping: rbac-defaults | ||||
| name: system:kube-apiserver-to-kubelet | ||||
| rules: | ||||
| - apiGroups: | ||||
| - "" | ||||
| resources: | ||||
| - nodes/proxy | ||||
| - nodes/stats | ||||
| - nodes/log | ||||
| - nodes/spec | ||||
| - nodes/metrics | ||||
| verbs: | ||||
| - "*" | ||||
| EOF | ||||
| cat <<EOF | kubectl apply -f - | ||||
| apiVersion: rbac.authorization.k8s.io/v1 | ||||
| kind: ClusterRoleBinding | ||||
| metadata: | ||||
| name: system:kube-apiserver | ||||
| namespace: "" | ||||
| roleRef: | ||||
| apiGroup: rbac.authorization.k8s.io | ||||
| kind: ClusterRole | ||||
| name: system:kube-apiserver-to-kubelet | ||||
| subjects: | ||||
| - apiGroup: rbac.authorization.k8s.io | ||||
| kind: User | ||||
| name: kubernetes | ||||
| EOF | ||||
| if [ "$cni" = "calico" ]; then | ||||
| INFO "Installing calico" | ||||
| set -x | ||||
| kubectl create -f ${base}/manifests/calico/tigera-operator.yaml | ||||
| ${base}/manifests/calico/custom-resources.sh | ||||
| set +x | ||||
| sleep 30 | ||||
| fi | ||||
| INFO "Installing CoreDNS" | ||||
| set -x | ||||
| # sleep for waiting the node to be available | ||||
|
|
@@ -457,7 +516,7 @@ if systemctl --user -q is-active u7s-master.target; then | |||
| INFO "Waiting for CoreDNS pods to be available" | ||||
| set -x | ||||
| # sleep for waiting the pod object to be created | ||||
| sleep 3 | ||||
| sleep 10 | ||||
| kubectl -n kube-system wait --for=condition=ready pod -l k8s-app=kube-dns | ||||
| kubectl get pods -A -o wide | ||||
| set +x | ||||
|
|
||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,34 @@ | ||
| #!/bin/bash | ||
| export U7S_BASE_DIR=$(realpath $(dirname $0)/../..) | ||
| source $U7S_BASE_DIR/common/common.inc.sh | ||
|
|
||
| mkdir -p $XDG_RUNTIME_DIR/usernetes/calico | ||
| cat >$XDG_RUNTIME_DIR/usernetes/calico/custom-resources.yaml <<EOF | ||
| apiVersion: operator.tigera.io/v1 | ||
| kind: Installation | ||
| metadata: | ||
| name: default | ||
| spec: | ||
| # Configures Calico networking. | ||
| calicoNetwork: | ||
| # Note: The ipPools section cannot be modified post-install. | ||
| ipPools: | ||
| - blockSize: 26 | ||
| cidr: 10.88.0.0/16 | ||
| encapsulation: VXLANCrossSubnet | ||
| natOutgoing: Enabled | ||
| nodeSelector: all() | ||
| kubeletVolumePluginPath: "$XDG_DATA_HOME/usernetes/kubelet" | ||
| nonPrivileged: Enabled | ||
| flexVolumePath: "$XDG_DATA_HOME/usernetes/kubelet-plugins-exec" | ||
|
|
||
| --- | ||
| apiVersion: operator.tigera.io/v1 | ||
| kind: APIServer | ||
| metadata: | ||
| name: default | ||
| spec: {} | ||
| EOF | ||
|
|
||
| exec $U7S_BASE_DIR/boot/nsenter.sh kubectl \ | ||
| create -f "$XDG_RUNTIME_DIR/usernetes/calico/custom-resources.yaml" |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,10 @@ | ||
| apiVersion: v1 | ||
| kind: EncryptionConfig | ||
| resources: | ||
| - resources: | ||
| - secrets | ||
| providers: | ||
| - secretbox: | ||
| keys: | ||
| - name: secrets_key | ||
| secret: $ENCRYPTION_SECRET |
Uh oh!
There was an error while loading. Please reload this page.