[stable/gocd] Add support for SSH keys on server and agent (New PR Cr… (#7084)

* [stable/gocd] Add support for SSH keys on server and agent (New PR Created)

* Updating change log

* Adding seperate ssh secrets for gocd server and agent

* Updating the default ssh secret name for agent and server

* Updating the README to move the ssh key properties and description to agent and server seperately
This commit is contained in:
Dilip Nandakumar
2018-08-10 09:04:29 -07:00
committed by k8s-ci-robot
parent c0eb1acd38
commit bcf3138b8c
6 changed files with 84 additions and 5 deletions
+4
View File
@@ -1,3 +1,7 @@
### 1.3.0
* [750de42c](https://github.com/kubernetes/charts/commit/750de42c): Add support for SSH keys on server and agent
### 1.2.0
* [514a1856](https://github.com/kubernetes/charts/commit/514a1856): Bump up GoCD app version to 18.7.0
+1 -1
View File
@@ -1,6 +1,6 @@
name: gocd
home: https://www.gocd.org/
version: 1.2.1
version: 1.3.0
appVersion: 18.7.0
description: GoCD is an open-source continuous delivery server to model and visualize complex workflows with ease.
icon: https://gocd.github.io/assets/images/go-icon-black-192x192.png
+33
View File
@@ -89,6 +89,8 @@ The following tables list the configurable parameters of the GoCD chart and thei
| `server.healthCheck.initialDelaySeconds` | Initial delays in seconds to start the health checks. **Note**:GoCD server start up time. | `90` |
| `server.healthCheck.periodSeconds` | GoCD server health check interval period. | `15` |
| `server.healthCheck.failureThreshold` | Number of unsuccessful attempts made to the GoCD server health check endpoint before restarting. | `10` |
| `server.security.ssh.enabled` | Enable the use of SSH keys for GoCD server | `false` |
| `server.security.ssh.secretName` | The name of the secret holding the SSH keys | `gocd-server-ssh` |
#### Preconfiguring the GoCD Server
@@ -130,6 +132,21 @@ The cases when the attempt to preconfigure the GoCD server fails:
1. The service account token mounted as a secret for the GoCD server pod does not have sufficient permissions. The API call to configure the plugin settings will fail.
2. If the GoCD server is started with an existing configuration with security configured, then the API calls in the preconfigure script will fail.
#### SSH keys
For accessing repositories over SSH in GoCD server, you need to add SSH keys to the GoCD server.
Generate a new keypair, fetch the host key for the [host] you want to connect to and create the secret.
The secret is structured to hold the entire contents of the .ssh folder on the GoCD server.
```bash
$ ssh-keygen -t rsa -b 4096 -C "user@example.com" -f gocd-server-ssh -P ''
$ ssh-keyscan [host] > gocd_known_hosts
$ kubectl create secret generic gocd-server-ssh \
--from-file=id_rsa=gocd-server-ssh \
--from-file=id_rsa.pub=gocd-server-ssh.pub \
--from-file=known_hosts=gocd_known_hosts
```
The last step is to copy the key over to the host, so GoCD server can connect.
### GoCD Agent
| Parameter | Description | Default |
@@ -151,6 +168,8 @@ The cases when the attempt to preconfigure the GoCD server fails:
| `agent.healthCheck.initialDelaySeconds` | GoCD agent start up time. | `60` |
| `agent.healthCheck.periodSeconds` | GoCD agent health check interval period. | `60` |
| `agent.healthCheck.failureThreshold` | GoCD agent health check failure threshold. Number of unsuccessful attempts made to the GoCD server health check endpoint before restarting. | `60` |
| `agent.security.ssh.enabled` | Enable the use of SSH keys for GoCD agent | `false` |
| `agent.security.ssh.secretName` | The name of the secret holding the SSH keys | `gocd-agent-ssh` |
Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`.
@@ -162,6 +181,20 @@ $ helm install --namespace gocd --name gocd-app -f values.yaml stable/gocd
> **Tip**: You can use the default [values.yaml](values.yaml)
#### SSH keys
For accessing repositories over SSH in GoCD agent, you need to add SSH keys to the GoCD agent.
Generate a new keypair, fetch the host key for the [host] you want to connect to and create the secret.
The secret is structured to hold the entire contents of the .ssh folder on the GoCD agent.
```bash
$ ssh-keygen -t rsa -b 4096 -C "user@example.com" -f gocd-agent-ssh -P ''
$ ssh-keyscan [host] > gocd_known_hosts
$ kubectl create secret generic gocd-agent-ssh \
--from-file=id_rsa=gocd-agent-ssh \
--from-file=id_rsa.pub=gocd-agent-ssh.pub \
--from-file=known_hosts=gocd_known_hosts
```
The last step is to copy the key over to the host, so GoCD agent can connect.
## Persistence
@@ -22,12 +22,19 @@ spec:
release: {{ .Release.Name | quote }}
component: agent
spec:
{{- if .Values.agent.persistence.enabled }}
{{- if or .Values.agent.persistence.enabled .Values.agent.security.ssh.enabled }}
volumes:
{{- end }}
{{- if .Values.agent.persistence.enabled }}
- name: goagent-vol
persistentVolumeClaim:
claimName: {{ .Values.agent.persistence.existingClaim | default (printf "%s-%s" (include "gocd.fullname" .) "agent") }}
{{- end }}
{{- if .Values.agent.security.ssh.enabled }}
- name: ssh-secrets
secret:
secretName: {{ .Values.agent.security.ssh.secretName }}
{{- end }}
containers:
- name: {{ template "gocd.name" . }}-agent
{{- if .Values.agent.image.tag }}
@@ -88,8 +95,10 @@ spec:
port: 8152
initialDelaySeconds: {{ .Values.agent.healthCheck.initialDelaySeconds }}
{{- end }}
{{- if .Values.agent.persistence.enabled }}
{{- if or .Values.agent.persistence.enabled .Values.agent.security.ssh.enabled }}
volumeMounts:
{{- end }}
{{- if .Values.agent.persistence.enabled }}
- name: goagent-vol
mountPath: /home/go
subPath: {{ .Values.agent.persistence.subpath.homego }}
@@ -97,6 +106,11 @@ spec:
mountPath: /docker-entrypoint.d
subPath: {{ .Values.agent.persistence.subpath.dockerEntryPoint }}
{{- end }}
{{- if .Values.agent.security.ssh.enabled }}
- name: ssh-secrets
readOnly: true
mountPath: /home/go/.ssh
{{- end }}
{{- if .Values.nodeSelector }}
nodeSelector:
{{ toYaml .Values.agent.nodeSelector | indent 8 }}
@@ -26,8 +26,10 @@ spec:
component: server
spec:
serviceAccountName: {{ template "gocd.serviceAccountName" . }}
{{- if .Values.server.persistence.enabled }}
{{- if or .Values.server.persistence.enabled .Values.server.security.ssh.enabled }}
volumes:
{{- end }}
{{- if .Values.server.persistence.enabled }}
- name: goserver-vol
persistentVolumeClaim:
claimName: {{ .Values.server.persistence.existingClaim | default (printf "%s-%s" (include "gocd.fullname" .) "server") }}
@@ -35,6 +37,11 @@ spec:
configMap:
name: {{ template "gocd.fullname" . }}
{{- end }}
{{- if .Values.server.security.ssh.enabled }}
- name: ssh-secrets
secret:
secretName: {{ .Values.server.security.ssh.secretName }}
{{- end }}
containers:
- name: {{ template "gocd.name" . }}-server
{{- if .Values.server.image.tag }}
@@ -68,8 +75,10 @@ spec:
initialDelaySeconds: {{ .Values.server.healthCheck.initialDelaySeconds }}
periodSeconds: {{ .Values.server.healthCheck.periodSeconds }}
failureThreshold: {{ .Values.server.healthCheck.failureThreshold }}
{{- if .Values.server.persistence.enabled }}
{{- if or .Values.server.persistence.enabled .Values.server.security.ssh.enabled }}
volumeMounts:
{{- end }}
{{- if .Values.server.persistence.enabled }}
- name: goserver-vol
mountPath: /godata
subPath: {{ .Values.server.persistence.subpath.godata }}
@@ -83,6 +92,11 @@ spec:
mountPath: /preconfigure_server.sh
subPath: preconfigure_server.sh
{{- end }}
{{- if .Values.server.security.ssh.enabled }}
- name: ssh-secrets
readOnly: true
mountPath: /home/go/.ssh
{{- end }}
{{- if .Values.server.shouldPreconfigure }}
lifecycle:
postStart:
+14
View File
@@ -129,6 +129,13 @@ server:
# custom entrypoint scripts that should be run before starting the GoCD server inside the container.
dockerEntryPoint: scripts
security:
ssh:
# server.security.ssh.enabled is the toggle to enable/disable mounting of ssh secret on GoCD server pods
enabled: false
# server.security.ssh.secretName specifies the name of the k8s secret object that contains the ssh key and known hosts
secretName: gocd-server-ssh
agent:
# agent.replicaCount is the GoCD Agent replicas Count. Specify the number of GoCD agents to run
replicaCount: 0
@@ -188,6 +195,13 @@ agent:
# agent.healthCheck.failureThreshold is the health check failure threshold of GoCD agent
failureThreshold: 60
security:
ssh:
# agent.security.ssh.enabled is the toggle to enable/disable mounting of ssh secret on GoCD agent pods
enabled: false
# agent.security.ssh.secretName specifies the name of the k8s secret object that contains the ssh key and known hosts
secretName: gocd-agent-ssh
## Configure GoCD agent resource requests and limits
## ref: http://kubernetes.io/docs/user-guide/compute-resources/
##