rancher / helm-locker Goto Github PK
View Code? Open in Web Editor NEWLicense: Apache License 2.0
License: Apache License 2.0
Need to add the ability to keep a HelmRelease unlocked after deployment
INFO[48281] applied cattle-monitoring-system/rancher-monitoring
E0415 08:42:35.218052 4898 leaderelection.go:367] Failed to update lock: Put "https://ronhead2.qa.rancher.space/k8s/clusters/c-k56pq/api/v1/namespaces/cattle-helm-system/configmaps/helm-locker-lock": net/http: TLS handshake timeout
Saw this this morning.
Note: cross-posted from https://github.com/aiyengar2/helm-locker/issues/7 on behalf of @ronhorton
Testing whether this works
Need unit, integration, and validation tests to be written in this repository to ensure that regressions can be caught as part of a CI process.
If you have a Helm release deployed but you don't want Helm Locker to reconcile changes to certain resources (identified by GVK), certain subsets of the spec of those resources (e.g. .spec.containers
to allow something like Istio to inject a sidecar), or you want certain patches to be applied (e.g. adding nodeSelectors and tolerations to all Workloads deployed by the Helm chart), you need the ability to specify these configurations and persist them to the cluster for Helm Locker to use.
HelmLockerPolicy is a proposed resource that would select a list of HelmReleases (by label selector) and modify the apply call made to the ObjectSet on behalf of the HelmRelease to add an apply.Patcher
to it that does custom sanitization based on the reconcile action provided.
The example manifest deploying a HelmLockerPolicy would look something like this:
kind: HelmLockerPolicy
apiVersion: helm.cattle.io/v1alpha1
metadata:
name: allow-partial-mutation-on-configmaps
namespace: cattle-helm-system
spec:
releaseSelector: # required, identifies which HelmRelease objects are selected by metav1.labelSelector. If not provided, this policy is a noop. This HelmLockerPolicy will only apply to HelmRelease CRs in the same namespace as itself.
matchLabels:
helm.cattle.io/configmaps: partially-mutable # example label to use
policies:
- apiVersion: v1 # required
kind: ConfigMap # required
name: my-config-map # optional, mutually exclusive with .spec.policies[i].selector. If both are provided, this will be chosen.
selector: # optional, mutually exclusive with .spec.policies[i].name
matchLabels:
myworkload: true
apply: # optional, the map provided here will override the values provided in the manifest for all targeted resources before they are parsed into an ObjectSet. It will not be validated that these patches are valid on the targeted resource, but if they are invalid the HelmRelease that selects this will be marked with the status FailedToApplyPolicy. If multiple selected patchers try to modify the same field, the HelmRelease will also be marked FailedToApplyPolicy. If you need to modify a list, provide _i (e.g. _1, _2, etc.) as the key to the map to indicate changes to resources in that index.
data:
config: "hello: world"
ignorePaths: # paths that should be ignored on reconciling changes
- '.data.config' # marks a path on which changes made are ignored. Providing `.` here will mark all paths as ignored and will allow changes to occur, although the resource will still be watched and recreated on deletion
Add ability to attach a ValidatingWebhookConfiguration to a /validate
endpoint of Helm Locker that denies changes to objects tracked by an ObjectSet before they are persisted.
This is a safer option that overwriting changes that are introduced.
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.