From fdca1f3237d16fea08939a8355ce9f27d09bd618 Mon Sep 17 00:00:00 2001 From: Giacomo Longo Date: Thu, 21 Nov 2019 09:59:28 +0100 Subject: [PATCH] [stable/gangway] Update to 3.2.0 (#18749) Signed-off-by: Giacomo Longo --- stable/gangway/Chart.yaml | 4 +- stable/gangway/README.md | 94 ++++++++++++------------ stable/gangway/templates/deployment.yaml | 2 +- stable/gangway/templates/ingress.yaml | 4 + stable/gangway/values.yaml | 2 +- 5 files changed, 55 insertions(+), 51 deletions(-) diff --git a/stable/gangway/Chart.yaml b/stable/gangway/Chart.yaml index b79ff5d66e..2aa8bf42b1 100644 --- a/stable/gangway/Chart.yaml +++ b/stable/gangway/Chart.yaml @@ -1,8 +1,8 @@ apiVersion: v1 description: An application that can be used to easily enable authentication flows via OIDC for a kubernetes cluster. name: gangway -version: 0.3.2 -appVersion: 3.0.0 +version: 0.4.0 +appVersion: 3.3.0 home: https://github.com/heptiolabs/gangway sources: - https://github.com/heptiolabs/gangway diff --git a/stable/gangway/README.md b/stable/gangway/README.md index 34de382ff6..69e9ebb4af 100644 --- a/stable/gangway/README.md +++ b/stable/gangway/README.md @@ -32,53 +32,53 @@ All values under the `gangway` top level object are passed directly to the Gangw At a minimum you *must* configure any of the values marked as **required** in the table below. -| Parameter | Description | Default | -| --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------- | -| `affinity` | List of affinities (requires Kubernetes >=1.6) | `{}` | -| `extraVolumes` | List of extra volumes | `[]` | -| `extraVolumeMounts` | List of extra volumeMounts | `[]` | -| `gangway.allowEmptyClientSecret` | Some identity providers accept an empty client secret, this is not generally considered a good idea. If you have to use an empty secret and accept the risks that come with that then you can set this to true. | `false` | -| `gangway.apiServerURL` | The API server endpoint used to configure kubectl. **Required** | `""` | -| `gangway.audience` | Endpoint that provides user profile information [optional]. Not all providers will require this. To be taken from the configuration of your OIDC provider. **Required** | `""` | -| `gangway.authorizeURL` | OAuth2 URL to start authorization flow. To be taken from the configuration of your OIDC provider. **Required** | `""` | -| `gangway.certFile` | The public cert file (including root and intermediates) to use when serving TLS. | `/etc/gangway/tls/tls.crt` | -| `gangway.clientID` | API client ID as indicated by the identity provider. **Required** | `""` | -| `gangway.clientSecret` | API client secret as indicated by the identity provider. **Required** | `""` | -| `gangway.cluster_ca_path` | The path to find the CA bundle for the API server. Used to configure kubectl. This is typically mounted into the default location for workloads running on a Kubernetes cluster and doesn't need to be set. | `""` | -| `gangway.clusterName` | The cluster name. Used in UI and kubectl config instructions. **Required** | `""` | -| `gangway.host` | The address to listen on. Defaults to 0.0.0.0 to listen on all interfaces. | `80` | -| `gangway.httpPath` | The path gangway uses to create urls (defaults to "") | `/` | -| `gangway.keyFile` | The private key file when serving TLS. | `/etc/gangway/tls/tls.key` | -| `gangway.port` | The port to listen on. Defaults to 8080. | `80` | -| `gangway.redirectURL` | Where to redirect back to. This should be a URL where gangway is reachable. Typically this also needs to be registered as part of the oauth application with the oAuth provider. **Required** | `""` | -| `gangway.scopes` | Used to specify the scope of the requested Oauth authorization. | `["openid", "profile", "email", "offline_access"]` | -| `gangway.serveTLS` | Should Gangway serve TLS vs. plain HTTP? | `false` | -| `gangway.sessionKey` | Encryption key for cookie contents. Will autogenerate if not provided. Caution: Do not use auto generation in production environments. | `""` | -| `gangway.tokenURL` | OAuth2 URL to obtain access tokens. To be taken from the configuration of your OIDC provider. **Required** | `""` | -| `gangway.trustedCAPath` | The path to a root CA to trust for self signed certificates at the Oauth2 URLs | `""` | -| `gangway.usernameClaim` | The JWT claim to use as the username. This is used in UI. Default is "nickname". This is combined with the clusterName for the "user" portion of the kubeconfig. | `name` | -| `trustedCACert` | Specify a CA cert to trust for self signed certificates at the Oauth2 URLs. | `""` | -| `image.repository` | Container image name (Including repository name if not `hub.docker.com`). | `gcr.io/heptio-images/gangway` | -| `image.pullPolicy` | Container pull policy. | `IfNotPresent` | -| `image.tag` | Container image tag. | `v2.2.0` | -| `image.pullSecrets` | Name of Secret resource containing private registry credentials | `""` | -| `ingress.annotations` | Ingress annotations | `{}` | -| `ingress.enabled` | Enables or Disables the ingress resource | `false` | -| `ingress.hosts` | List of FQDN's for the ingress | `""` | -| `ingress.tls.hosts` | List of FQDN's the above secret is associated with | `""` | -| `ingress.tls.secretName` | Name of the secret to use | `""` | -| `ingress.tls` | List of SSL certs to use | `""` | -| `livenessProbe.scheme` | Scheme to use for httpGet probe, `HTTP` or `HTTPS`. | `HTTP` | -| `nodeSelector` | Node labels for pod assignment | `{}` | -| `podAnnotations` | Additional annotations to apply to the pod. | `{}` | -| `resources` | CPU/Memory resource requests/limits. | `{}` | -| `readinessProbe.scheme` | Scheme to use for httpGet probe, `HTTP` or `HTTPS`. | `HTTP` | -| `service.port` | The port the service should listen on | `80` | -| `service.type` | Type of service to create | `ClusterIP` | -| `tls.certData` | The Public cert data. This is normally safe to leave alone. | `""` | -| `tls.existingSecret` | An existing secret with a `tls.crt` and `tls.key` | `""` | -| `tls.keyData` | The Private key data | `""` | -| `tolerations` | List of node taints to tolerate (requires Kubernetes >= 1.6) | `[]` | +| Parameter | Description | Default | +| -------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------- | +| `affinity` | List of affinities (requires Kubernetes >=1.6) | `{}` | +| `extraVolumes` | List of extra volumes | `[]` | +| `extraVolumeMounts` | List of extra volumeMounts | `[]` | +| `gangway.allowEmptyClientSecret` | Some identity providers accept an empty client secret, this is not generally considered a good idea. If you have to use an empty secret and accept the risks that come with that then you can set this to true. | `false` | +| `gangway.apiServerURL` | The API server endpoint used to configure kubectl. **Required** | `""` | +| `gangway.audience` | Endpoint that provides user profile information [optional]. Not all providers will require this. To be taken from the configuration of your OIDC provider. **Required** | `""` | +| `gangway.authorizeURL` | OAuth2 URL to start authorization flow. To be taken from the configuration of your OIDC provider. **Required** | `""` | +| `gangway.certFile` | The public cert file (including root and intermediates) to use when serving TLS. | `/etc/gangway/tls/tls.crt` | +| `gangway.clientID` | API client ID as indicated by the identity provider. **Required** | `""` | +| `gangway.clientSecret` | API client secret as indicated by the identity provider. **Required** | `""` | +| `gangway.cluster_ca_path` | The path to find the CA bundle for the API server. Used to configure kubectl. This is typically mounted into the default location for workloads running on a Kubernetes cluster and doesn't need to be set. | `""` | +| `gangway.clusterName` | The cluster name. Used in UI and kubectl config instructions. **Required** | `""` | +| `gangway.host` | The address to listen on. Defaults to 0.0.0.0 to listen on all interfaces. | `80` | +| `gangway.httpPath` | The path gangway uses to create urls (defaults to "") | `/` | +| `gangway.keyFile` | The private key file when serving TLS. | `/etc/gangway/tls/tls.key` | +| `gangway.port` | The port to listen on. Defaults to 8080. | `80` | +| `gangway.redirectURL` | Where to redirect back to. This should be a URL where gangway is reachable. Typically this also needs to be registered as part of the oauth application with the oAuth provider. **Required** | `""` | +| `gangway.scopes` | Used to specify the scope of the requested Oauth authorization. | `["openid", "profile", "email", "offline_access"]` | +| `gangway.serveTLS` | Should Gangway serve TLS vs. plain HTTP? | `false` | +| `gangway.sessionKey` | Encryption key for cookie contents. Will autogenerate if not provided. Caution: Do not use auto generation in production environments. | `""` | +| `gangway.tokenURL` | OAuth2 URL to obtain access tokens. To be taken from the configuration of your OIDC provider. **Required** | `""` | +| `gangway.trustedCAPath` | The path to a root CA to trust for self signed certificates at the Oauth2 URLs | `""` | +| `gangway.usernameClaim` | The JWT claim to use as the username. This is used in UI. Default is "nickname". This is combined with the clusterName for the "user" portion of the kubeconfig. | `name` | +| `trustedCACert` | Specify a CA cert to trust for self signed certificates at the Oauth2 URLs. | `""` | +| `image.repository` | Container image name (Including repository name if not `hub.docker.com`). | `gcr.io/heptio-images/gangway` | +| `image.pullPolicy` | Container pull policy. | `IfNotPresent` | +| `image.tag` | Container image tag. | `v3.2.0` | +| `image.pullSecrets` | Name of Secret resource containing private registry credentials | `""` | +| `ingress.annotations` | Ingress annotations | `{}` | +| `ingress.enabled` | Enables or Disables the ingress resource | `false` | +| `ingress.hosts` | List of FQDN's for the ingress | `""` | +| `ingress.tls.hosts` | List of FQDN's the above secret is associated with | `""` | +| `ingress.tls.secretName` | Name of the secret to use | `""` | +| `ingress.tls` | List of SSL certs to use | `""` | +| `livenessProbe.scheme` | Scheme to use for httpGet probe, `HTTP` or `HTTPS`. | `HTTP` | +| `nodeSelector` | Node labels for pod assignment | `{}` | +| `podAnnotations` | Additional annotations to apply to the pod. | `{}` | +| `resources` | CPU/Memory resource requests/limits. | `{}` | +| `readinessProbe.scheme` | Scheme to use for httpGet probe, `HTTP` or `HTTPS`. | `HTTP` | +| `service.port` | The port the service should listen on | `80` | +| `service.type` | Type of service to create | `ClusterIP` | +| `tls.certData` | The Public cert data. This is normally safe to leave alone. | `""` | +| `tls.existingSecret` | An existing secret with a `tls.crt` and `tls.key` | `""` | +| `tls.keyData` | The Private key data | `""` | +| `tolerations` | List of node taints to tolerate (requires Kubernetes >= 1.6) | `[]` | You will likely want to expose Gangway to your users somehow, possibly by way of an ingress, the values below would be a way of doing this with the [Traefik] ingress controller, this assumes TLS offload is happening at the load balancer: diff --git a/stable/gangway/templates/deployment.yaml b/stable/gangway/templates/deployment.yaml index 8381ea9908..99aa68305f 100644 --- a/stable/gangway/templates/deployment.yaml +++ b/stable/gangway/templates/deployment.yaml @@ -1,4 +1,4 @@ -apiVersion: apps/v1beta2 +apiVersion: apps/v1 kind: Deployment metadata: name: {{ include "gangway.fullname" . }} diff --git a/stable/gangway/templates/ingress.yaml b/stable/gangway/templates/ingress.yaml index db38403270..bbeec012a5 100644 --- a/stable/gangway/templates/ingress.yaml +++ b/stable/gangway/templates/ingress.yaml @@ -1,7 +1,11 @@ {{- if .Values.ingress.enabled -}} {{- $fullName := include "gangway.fullname" . -}} {{- $ingressPath := .Values.ingress.path -}} +{{- if $.Capabilities.APIVersions.Has "networking.k8s.io/v1beta1" }} +apiVersion: networking.k8s.io/v1beta1 +{{- else }} apiVersion: extensions/v1beta1 +{{- end }} kind: Ingress metadata: name: {{ $fullName }} diff --git a/stable/gangway/values.yaml b/stable/gangway/values.yaml index 6bc8aa154d..4c5c69fa07 100644 --- a/stable/gangway/values.yaml +++ b/stable/gangway/values.yaml @@ -2,7 +2,7 @@ replicaCount: 1 image: repository: gcr.io/heptio-images/gangway - tag: v3.0.0 + tag: v3.2.0 pullPolicy: IfNotPresent ## Optional array of imagePullSecrets containing private registry credentials ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/