diff --git a/stable/hlf-ca/Chart.yaml b/stable/hlf-ca/Chart.yaml index cd7a815164..59ccf53947 100644 --- a/stable/hlf-ca/Chart.yaml +++ b/stable/hlf-ca/Chart.yaml @@ -1,7 +1,7 @@ apiVersion: v1 description: Hyperledger Fabric Certificate Authority chart (these charts are created by AID:Tech and are currently not directly associated with the Hyperledger project) name: hlf-ca -version: 1.1.0 +version: 1.1.1 appVersion: 1.2.0 keywords: - blockchain diff --git a/stable/hlf-ca/README.md b/stable/hlf-ca/README.md index 6bd2fc5bc2..d7024fe2b7 100644 --- a/stable/hlf-ca/README.md +++ b/stable/hlf-ca/README.md @@ -81,6 +81,7 @@ The following table lists the configurable parameters of the Hyperledger Fabric | `ingress.path` | Ingress path | `/` | | `ingress.hosts` | Ingress hostnames | `[]` | | `ingress.tls` | Ingress TLS configuration | `[]` | +| `persistence.existingClaim` | Name of an existing PVC to use for Fabric CA | `nil` | | `persistence.accessMode` | Use volume as ReadOnly or ReadWrite | `ReadWriteOnce` | | `persistence.annotations` | Persistent Volume annotations | `{}` | | `persistence.size` | Size of data volume | `1Gi` | @@ -88,8 +89,15 @@ The following table lists the configurable parameters of the Hyperledger Fabric | `adminUsername` | Admin Username for CA | `admin` | | `adminPassword` | Admin Password | Random 24 alphanumeric characters | | `caName` | Name of CA | `org1-ca` | -| `db.chart` | Name of a Database Chart holding CA data | `` supports postgresql | -| `db.database` | Name of the actual Database holding the CA data | `fabric_ca` | +| `db.ssl` | SSL Authentication | `disable` | +| `postgresql.enabled` | Deploy a PostgreSQL container holding the CA data | `false` | +| `mysql.enabled` | Deploy a MySQL container holding the CA data | `false` | +| `externalDatabase.type` | Database type (either `postgres` or `mysql` ) | `nil` | +| `externalDatabase.host` | Host of the external database | `localhost` | +| `externalDatabase.username` | Existing username in the external db | `` | +| `externalDatabase.password` | Password for the above username | `` | +| `externalDatabase.database` | Name of the existing database | `` | +| `externalDatabase.port` | Database port number | `` | | `config.hlfToolsVersion` | Version of Hyperledger Fabric tools used | `1.1.0` | | `config.mountTLS` | If TLS secrets are generated, do we mount them? | `false` | | `config.debug` | Enable debug logging | `true` | @@ -109,6 +117,43 @@ The following table lists the configurable parameters of the Hyperledger Fabric | `tolerations` | Toleration labels for pod assignment | `[]` | | `affinity` | Affinity settings for pod assignment | `{}` | +## Database + +The Fabric CA server needs a database to store the users registered. + +By default the chart is configured to use an in-memory `sqlite3` database, but you can also configure the helm chart to install a `PostgreSQL` or a `MySQL` database along the Fabric CA server. + +### PostgreSQL + +To install a `postgresql` running in Kubernetes you have to enable and configure the `postgresql` section in `values.yaml` or pass the following parameter: + +``` + helm install stable/hlf-ca --name org1-ca --set postgresql.enabled=true +``` + +### MySQL + +To install a `mysql` running in Kubernetes you have to enable and configure the `mysql` section in `values.yaml` or pass the following parameter: + +``` + helm install stable/hlf-ca --name org1-ca --set mysql.enabled=true +``` + +### External Database + +In case you already setup a database (`postgres` or `mysql`), you can enable and configure the `externalDatabase` section in `values.yaml` or pass the following parameters:` + +``` + helm install stable/hlf-ca --name org1-ca \ + --set externalDatabase.type=mysql \ + --set externalDatabase.host=myhost \ + --set externalDatabase.username=myuser \ + --set externalDatabase.password=mypassword \ + --set externalDatabase.database=mydatabase +``` + +Please consult the [documentation](https://hyperledger-fabric-ca.readthedocs.io/en/latest/users-guide.html?highlight=database#configuring-the-database) for mode details. + ## Persistence The volume stores the Fabric_CA data and configurations at the `/var/hyperledger` path of the container. diff --git a/stable/hlf-ca/requirements.lock b/stable/hlf-ca/requirements.lock new file mode 100644 index 0000000000..22e007fc52 --- /dev/null +++ b/stable/hlf-ca/requirements.lock @@ -0,0 +1,9 @@ +dependencies: +- name: postgresql + repository: https://kubernetes-charts.storage.googleapis.com/ + version: 1.0.0 +- name: mysql + repository: https://kubernetes-charts.storage.googleapis.com/ + version: 0.10.1 +digest: sha256:1b5b212945abc2abc2317189f0d048b1c90f093db8ed5482db2c35a9d463259f +generated: 2018-10-22T16:32:44.32018675-04:00 diff --git a/stable/hlf-ca/requirements.yaml b/stable/hlf-ca/requirements.yaml new file mode 100644 index 0000000000..fe417af98e --- /dev/null +++ b/stable/hlf-ca/requirements.yaml @@ -0,0 +1,14 @@ +dependencies: +- name: postgresql + version: x.x.x + repository: https://kubernetes-charts.storage.googleapis.com/ + condition: postgresql.enabled + tags: + - postgres-database + +- name: mysql + version: x.x.x + repository: https://kubernetes-charts.storage.googleapis.com/ + condition: mysql.enabled + tags: + - mysql-database \ No newline at end of file diff --git a/stable/hlf-ca/templates/_helpers.tpl b/stable/hlf-ca/templates/_helpers.tpl index e7f6f95d75..a2faccb279 100644 --- a/stable/hlf-ca/templates/_helpers.tpl +++ b/stable/hlf-ca/templates/_helpers.tpl @@ -43,3 +43,17 @@ heritage: {{ .Release.Service | quote }} release: {{ .Release.Name | quote }} chart: {{ include "hlf-ca.chart" . }} {{- end -}} + +{{/* +Generate postgres chart name +*/}} +{{- define "postgresql.fullname" -}} +{{- printf "%s-%s" .Release.Name "postgresql" | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Generate mysql chart name +*/}} +{{- define "mysql.fullname" -}} +{{- printf "%s-%s" .Release.Name "mysql" | trunc 63 | trimSuffix "-" -}} +{{- end -}} diff --git a/stable/hlf-ca/templates/configmap--db.yaml b/stable/hlf-ca/templates/configmap--db.yaml index 9821c3dddf..c2e691eb09 100644 --- a/stable/hlf-ca/templates/configmap--db.yaml +++ b/stable/hlf-ca/templates/configmap--db.yaml @@ -5,14 +5,33 @@ metadata: labels: {{ include "labels.standard" . | indent 4 }} data: - # TODO: Enable multiple types of database, not only PostgreSQL - DB_TYPE: postgres - DB_USERNAME: postgres - DB_DATABASE: {{ .Values.db.database | quote }} - {{- if .Values.db.chart }} - DB_HOST: {{ .Values.db.chart }}.{{ .Release.Namespace }}.svc.cluster.local - {{- else }} - DB_HOST: localhost + DB_SSL: {{ .Values.db.ssl | quote }} + {{- if .Values.postgresql.enabled }} + # PostgreSQL Database + DB_TYPE: "postgres" + DB_HOST: {{ template "postgresql.fullname" . }} + DB_PORT: {{ .Values.postgresql.port | quote }} + DB_USERNAME: {{ .Values.postgresql.postgresUser | quote }} + DB_DATABASE: {{ .Values.postgresql.postgresDatabase | quote }} {{- end }} - DB_PORT: "5432" - DB_SSL: disable + {{- if .Values.mysql.enabled }} + # MySQL Database + DB_TYPE: "mysql" + DB_HOST: {{ template "mysql.fullname" . }} + DB_PORT: "3306" + DB_USERNAME: {{ .Values.mysql.mysqlUser | quote }} + DB_DATABASE: {{ .Values.mysql.mysqlDatabase | quote }} + {{- end }} + {{- if .Values.externalDatabase.type }} + # External Database + DB_TYPE: {{ .Values.externalDatabase.type | quote }} + DB_HOST: {{ .Values.externalDatabase.host | quote }} + {{- if eq .Values.externalDatabase.type "mysql" }} + DB_PORT: {{ .Values.externalDatabase.port | default "3306" | quote }} + {{- end }} + {{- if eq .Values.externalDatabase.type "postgres" }} + DB_PORT: {{ .Values.externalDatabase.port | default "5432" | quote }} + {{- end }} + DB_USERNAME: {{ .Values.externalDatabase.username | quote }} + DB_DATABASE: {{ .Values.externalDatabase.database | quote }} + {{- end }} \ No newline at end of file diff --git a/stable/hlf-ca/templates/deployment.yaml b/stable/hlf-ca/templates/deployment.yaml index 989021a72d..2b06e53d39 100644 --- a/stable/hlf-ca/templates/deployment.yaml +++ b/stable/hlf-ca/templates/deployment.yaml @@ -30,55 +30,95 @@ spec: {{- end }} - name: ca-config configMap: - name: {{ include "hlf-ca.fullname" . }}--config + name: {{ include "hlf-ca.fullname" . }}--config + initContainers: + - name: wait-for-db + image: jwilder/dockerize + imagePullPolicy: IfNotPresent + envFrom: + - configMapRef: + name: {{ include "hlf-ca.fullname" . }}--db + command: + - sh + - -c + - | + if [ -n "$DB_TYPE" ]; then + dockerize -wait tcp://$DB_HOST:$DB_PORT -timeout 30s && echo "Database $DB_TYPE on $DB_HOST:$DB_PORT is ready" + fi containers: - name: ca image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" imagePullPolicy: {{ .Values.image.pullPolicy }} - # TODO: Add liveness and readiness probes (for health checks) command: - sh - -c - | - while [ -z ${DB_PASSWORD+x} ]; - do - echo "\033[0;31m DB_PASSWORD environmental variable must contain a value (check that you specified 'db.chart' in values.yaml) \033[0m" - sleep 60 - done + if [ -n "$DB_TYPE" ]; then + while [ -z ${DB_PASSWORD+x} ]; + do + echo "\033[0;31mDB_PASSWORD environmental variable must contain a value \033[0m" + sleep 60 + done + + case "$DB_TYPE" in + postgres) + export DB_DATASOURCE="host=${DB_HOST} port=${DB_PORT} user=${DB_USERNAME} password=${DB_PASSWORD} dbname=${DB_DATABASE} sslmode=${DB_SSL}";; + mysql) + export DB_DATASOURCE="${DB_USERNAME}:${DB_PASSWORD}@tcp(${DB_HOST}:${DB_PORT})/${DB_DATABASE}?parseTime=true" ;; + *) + echo "\033[0;31m Database type '$DB_TYPE' not supported\033[0m"; exit 1;; + esac + fi - export DB_DATASOURCE="host=${DB_HOST} port=${DB_PORT} user=${DB_USERNAME} password=${DB_PASSWORD} dbname=${DB_DATABASE} sslmode=${DB_SSL}" mkdir -p $FABRIC_CA_HOME cp /var/hyperledger/ca_config/ca.yaml $FABRIC_CA_HOME/fabric-ca-server-config.yaml - sed -i "s/<<>>/${CA_ADMIN}/g" ${FABRIC_CA_HOME}/fabric-ca-server-config.yaml - sed -i "s/<<>>/${CA_PASSWORD}/g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml - sed -i "s/<<>>/${DB_TYPE}/g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml - sed -i "s/<<>>/${DB_DATASOURCE}/g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml + sed -i "s|<<>>|${CA_ADMIN}|g" ${FABRIC_CA_HOME}/fabric-ca-server-config.yaml + sed -i "s|<<>>|${CA_PASSWORD}|g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml + sed -i "s|<<>>|${DB_TYPE:-"sqlite3"}|g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml + sed -i "s|<<>>|${DB_DATASOURCE:-"fabric-ca-server.db"}|g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml {{- if .Values.config.intermediate }} - echo ">\033[0;33m Adding Parent CA (typically a Root CA) values to $FABRIC_CA_HOME/fabric-ca-server-config.yaml \033[0m" - sed -i "s/<<>>/${PARENT_CA_ADMIN}/g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml - sed -i "s/<<>>/${PARENT_CA_PASSWORD}/g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml + echo ">\033[0;33m Adding Parent CA (typically a Root CA) values to $FABRIC_CA_HOME/fabric-ca-server-config.yaml\033[0m" + sed -i "s|<<>>|${PARENT_CA_ADMIN}|g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml + sed -i "s|<<>>|${PARENT_CA_PASSWORD}|g" $FABRIC_CA_HOME/fabric-ca-server-config.yaml {{- end}} echo ">\033[0;35m fabric-ca-server start \033[0m" fabric-ca-server start envFrom: - secretRef: - name: {{ include "hlf-ca.fullname" . }} + name: {{ include "hlf-ca.fullname" . }}--ca - configMapRef: name: {{ include "hlf-ca.fullname" . }}--db - configMapRef: name: {{ include "hlf-ca.fullname" . }}--ca env: - # Database environmental variable - {{- if .Values.db.chart }} + {{- if .Values.postgresql.enabled}} + # PostgreSQL Database - name: DB_PASSWORD valueFrom: secretKeyRef: - name: {{ .Values.db.chart | quote }} + name: {{ template "postgresql.fullname" . }} key: postgres-password {{- end }} + {{- if .Values.mysql.enabled }} + # MySQL Database + - name: DB_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "mysql.fullname" . }} + key: mysql-password + {{- end }} + {{- if .Values.externalDatabase.type }} + # External Database + - name: DB_PASSWORD + valueFrom: + secretKeyRef: + name: {{ include "hlf-ca.fullname" . }}--db + key: db-password + {{- end }} {{- if .Values.config.intermediate }} + # Intermediate CA - name: PARENT_CA_ADMIN valueFrom: secretKeyRef: @@ -94,6 +134,14 @@ spec: - name: ca-port containerPort: 7054 protocol: TCP + livenessProbe: + httpGet: + path: /cainfo + port: 7054 + readinessProbe: + httpGet: + path: /cainfo + port: 7054 volumeMounts: - name: data mountPath: /var/hyperledger diff --git a/stable/hlf-ca/templates/secret.yaml b/stable/hlf-ca/templates/secret--ca.yaml similarity index 88% rename from stable/hlf-ca/templates/secret.yaml rename to stable/hlf-ca/templates/secret--ca.yaml index 342881ce5a..cf507c60e9 100644 --- a/stable/hlf-ca/templates/secret.yaml +++ b/stable/hlf-ca/templates/secret--ca.yaml @@ -1,7 +1,7 @@ apiVersion: v1 kind: Secret metadata: - name: {{ include "hlf-ca.fullname" . }} + name: {{ include "hlf-ca.fullname" . }}--ca labels: {{ include "labels.standard" . | indent 4 }} type: Opaque diff --git a/stable/hlf-ca/templates/secret--db.yaml b/stable/hlf-ca/templates/secret--db.yaml new file mode 100644 index 0000000000..b7d5011395 --- /dev/null +++ b/stable/hlf-ca/templates/secret--db.yaml @@ -0,0 +1,11 @@ +{{- if .Values.externalDatabase.type }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ include "hlf-ca.fullname" . }}--db + labels: +{{ include "labels.standard" . | indent 4 }} +type: Opaque +data: + db-password: {{ .Values.externalDatabase.password | b64enc | quote }} +{{- end }} \ No newline at end of file diff --git a/stable/hlf-ca/values.yaml b/stable/hlf-ca/values.yaml index 8aece1f419..34fac4b84f 100644 --- a/stable/hlf-ca/values.yaml +++ b/stable/hlf-ca/values.yaml @@ -49,10 +49,64 @@ adminUsername: admin ## Name of CA, stored in FABRIC_CA_SERVER_CA_NAME (and the configMap "--config", if deploying a Root CA) caName: org1-ca -## Settings used in configMap "--db" +## +## Fabric CA Database +## By default an sqlite3 in-memory database is used +## To install a 'postgresql' or 'mysql' database, enable and configure the configuration below +################################## +## db: - # chart: postgres-ca-postgresql - database: fabric_ca + # SSL authentication + # Supported values are: "disable", "require", "verify-ca" and "verify-full". + # https://github.com/hyperledger/fabric-ca/blob/master/docs/source/users-guide.rst + ssl: disable + +## +## PostgreSQL chart configuration +## +## https://github.com/helm/charts/tree/master/stable/postgresql +## +postgresql: + ## Whether to deploy a postgres server to satisfy the Fabric CA database requirements. + # To use an external database set this to false and configure the externalDatabase parameters, specifying the type to 'postgres' + enabled: false + image: "postgres" + imageTag: "9.6.2" + port: 5432 + postgresDatabase: fabric_ca + postgresUser: fabric_ca + +## +## MySQL chart configuration +## +## https://github.com/helm/charts/tree/master/stable/mysql +## +mysql: + ## Whether to deploy a mysql server to satisfy the Fabric CA database requirements. + # To use an external database set this to false and configure the externalDatabase parameters, specifying the type to 'mysql' + enabled: false + image: "mysql" + imageTag: "5.7.14" + mysqlDatabase: fabric_ca + mysqlUser: fabric_ca + # Custom mysql configuration to remove SQL Mode NO_ZERO_DATE because the Fabric CA schema defines TIMESTAMP to 0 by default + # https://dev.mysql.com/doc/refman/5.7/en/sql-mode.html + configurationFiles: + mysql.cnf: |- + [mysqld] + sql-mode=STRICT_TRANS_TABLES,NO_ZERO_IN_DATE,ERROR_FOR_DIVISION_BY_ZERO,NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION + +## +## External Database configuration (MySQL or PostgresSQL install outside Kubernetes) +## +externalDatabase: + # Either postgres or mysql + type: + host: "" + port: "" + database: "" + username: "" + password: "" ## Settings used in configMap "--config" config: