Commit Graph
164 Commits
Author SHA1 Message Date
Kubernetes Prow Robot 6de689e7e4 [stable/datadog] Revert "Mount the directory containing the CRI socket instead of the socket itself" (#21268)
This reverts commit 24b4881ecb9ae7c4368359d59df4fcc968493356.

Fixes #21223

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
2020-03-05 06:46:38 -08:00
Cedric LamoriniereandVincent Boulineau 1388bd5663 [stable/datadog][v2.0.1] improve logs fields (#21086)
Co-Authored-By: Vincent Boulineau <58430298+vboulineau@users.noreply.github.com>
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

Co-authored-by: Vincent Boulineau <58430298+vboulineau@users.noreply.github.com>
2020-02-27 11:15:28 -08:00
6d2fc82c22 [stable/datadog] v2.0.0 major release (#18182)
* [stable/datadog] v2.0.0 cleaning and refactoring

* Remove Datadog agent deployment configuration.
* Cleanup resources labels, to fit with recommended labels.
* Cleanup useless or unused values parameters.

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* [stable/datadog] cleanup refactor RBAC resources

* each component have its own RBAC configuration (create,configuration).
* container runtime socket update values configuration simplification.
* `nameOverride` `fullnameOverride` is now optional in values.yaml

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* update stable/datadog/ci values.yaml

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* [datadog] fix linter error

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* [datadog] fix missing merge

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* refactor values.yaml

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* update value.yaml

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* Add a table with the correspondence between the v1 and v2 parameters

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* templates: enable APM by default

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* Leave apm.enabled setting but change default.

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* DD_APM_NON_LOCAL_TRAFFIC=true when apm.enabled is true

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* Enable hostPort binding 8126 by default when apm.enabled is true.

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* values: make apm.enabled default to false

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* Address PR comments.

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* refactor dogstatsd parameters

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* update after comments

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* fix dogstatsd parameters path

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* update system-probe manifest after review

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* update ci configuration and fix cluster-agent config

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* change cluster-agent probes endpoint

change the cluster-agent probes endpoint in order to be resilent if
never the datadog api is not reachable.

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* Fix several typo thanks to contributions

Include: #20460 #20449

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* adding new approvers/reviewers

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* [stable/datadog] add resoures field for init-containers

Fixe: #20035
Include: #20461

Add the possibility to overwrite the resources associated to the
init-containers.

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* update after review

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* return error message if apiKey is not provided

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* Mount the directory containing the CRI socket instead of the socket itself (#5)

This is to handle the cases where the docker daemon is restarted.
In this case, the docker daemon will recreate its docker socket and,
if the container bind-mounted directly the socket, the container would
still have access to the old socket instead of the one of the new docker
daemon.

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

Co-authored-by: Lénaïc Huard <L3n41c@users.noreply.github.com>
Co-authored-by: Gabriel Aszalos <gabriel.aszalos@datadoghq.com>
2020-02-26 07:26:25 -08:00
MattTheCat 275d0344f3 add ability to use a configmap to provide the (#20744)
datadog-cluster.yaml config file

Signed-off-by: Matthew Gifford <matthew.gifford@railinc.com>
2020-02-16 13:29:27 -08:00
gml3ff f1b36a1013 [stable/datadog] clarify that nonLocalTraffic must be set to true to use APM (#20590)
* clarify that nonLocalTraffic must be set to true to use APM

Signed-off-by: Morgan Lupton <morgan.lupton@datadoghq.com>
Signed-off-by: gml3ff <morgan.lupton@datadoghq.com>

* bump chart version

Signed-off-by: gml3ff <morgan.lupton@datadoghq.com>
2020-02-06 14:51:24 -08:00
Ofek Lev aa8d3e94c1 Fix typo (#20066)
Signed-off-by: Ofek Lev <ofekmeister@gmail.com>
2020-02-06 02:57:33 -08:00
Lee Avital 75884aaa70 Add statfs to system-probe seccomp profile (#20451)
Signed-off-by: Lee Avital <lee.avital@datadoghq.com>
2020-01-30 10:42:19 -08:00
Danny Carrillo f4f9a2ccd6 [stable/datadog] Fixes issue with trace-agent only listening on localhost (#20328)
* Fixes issue with trace-agent only listening on localhost

Currently the `trace-agent` only listens on `localhost` regardless whether `nonLocalTraffic` is true or not.

This fixes that by checking if `nonLocalTraffic: true` then we set the correct environment variables in the trace-agent pods

Signed-off-by: Danny Carrillo <odannycx@gmail.com>

* Update Chart.yaml

Signed-off-by: Danny Carrillo <odannycx@gmail.com>
2020-01-24 10:28:32 -08:00
Ivan IlichevandCedric Lamoriniere 9292d70bda [stable/datadog] Make metricsProvider service port configurable (#20279)
* [stable/datadog] Make metricsProvider service port configurable via values

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

* Update stable/datadog/ci/cluster-agent-metrics-server-service-port-values.yaml

Co-Authored-By: Cedric Lamoriniere <cedric.lamoriniere@datadoghq.com>
Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

* Fix lint error - too many blank lines

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

* Fix liveness and readiness probe

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

Co-authored-by: Cedric Lamoriniere <cedric.lamoriniere@datadoghq.com>
2020-01-22 09:06:37 -08:00
jeffscelza 202645082a stable/datadog: Update datadog-yaml-configmap.yaml (#20200)
* Update datadog-yaml-configmap.yaml

Current configuration is causing issue with enabling APM for nonlocal traffic.
Here is what it currently looks like in the containers /etc/datadog/datadog.yaml file:

apm_config:
  enabled: false
  apm_non_local_traffic: true# tag 6 was introduce with 6.15

Signed-off-by: Jeffrey Scelza <jeffrey.scelza@checkr.com>

* Bumping up version of Datadog Chart

Signed-off-by: Jeffrey Scelza <jeffrey.scelza@checkr.com>
2020-01-21 02:35:37 -08:00
Cedric Lamoriniere f5b866c8cd [stable/datadog] fix dd_site and dd_dd_url env var (#19913)
Fix the usage of the `.Values.datadog.site` and `.Values.datadog.dd_url`
parameters when `.Values.daemonset.useDedicatedContainers` is activated.

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
2020-01-09 04:53:45 -08:00
Cedric Lamoriniere 8f30dd815f [stable/datadog] fix when (#19877)
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
2020-01-07 07:04:23 -08:00
Xavier Lucas d1a20aa610 Explicitly pin to agent 7 (#19700)
* Explicitly pin to agent 7

Signed-off-by: Xavier Lucas <xavier.lucas@datadoghq.com>

* Update chart version

Signed-off-by: Xavier Lucas <xavier.lucas@datadoghq.com>
2019-12-20 00:27:32 -08:00
Ivan Ilichev 7103e65f00 [stable/datadog] Allow providing volumes and mounts in the cluster agent deployment (#19679)
* Allow providing volumes and mounts in the cluster agent deployment

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

* Document volumes and volumeMounts for cluster agent in README

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

* Add a test for the volumes and volumeMounts

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

* Bump chart version

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

* Fix file ending

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>

* Rename the ci test and change to use a hostPath volume

Signed-off-by: Ivan Ilichev <ivan.ilichev@datadoghq.com>
2019-12-19 08:03:57 -08:00
Alex Jones 366b550f31 [stabel/datadog] fix syntax error in templates/datadog-yaml-configmap.yaml (#19676)
* fix syntax error in templates/datadog-yaml-configmap.yaml

Signed-off-by: Alex Jones <ajones@agari.com>

* Up chart version since new versions of the chart have been merged since PR was opened

Signed-off-by: Alex Jones <ajones@agari.com>
2019-12-18 09:41:57 -08:00
John Pekcan 9934b8ff41 [stable/datadog] allow dogstatsd port to be variable (#18966)
* [stable/datadog] allow dogstatsd port to be variable

Signed-off-by: John Pekcan <johnpekcan@gmail.com>

* need to uncomment customAgentConfig

Signed-off-by: John Pekcan <johnpekcan@gmail.com>

* leave dogstatsd port empty in values.yaml

Signed-off-by: John Pekcan <johnpekcan@gmail.com>

* spacing for comments

Signed-off-by: John Pekcan <johnpekcan@gmail.com>

* need to leave dogstatsd_port uncommented

Signed-off-by: John Pekcan <johnpekcan@gmail.com>

* taking feedback, moving var around

Signed-off-by: John Pekcan <johnpekcan@gmail.com>

* fixing camelCase, and adding env var for statsd

Signed-off-by: John Pekcan <johnpekcan@gmail.com>

* bumping version with sign off

Signed-off-by: John Pekcan <johnpekcan@gmail.com>

* relocating the param in readme

Signed-off-by: John Pekcan <johnpekcan@gmail.com>
2019-12-18 09:05:57 -08:00
Matt Klich c868b805f8 [stable/datadog] use 6.15, remove hard coded names/versions (#18930)
* Datadog: remove hard coded names

* The new system-probe container and config used hard coded CongigMap
names meaning only one installation is possible per cluster and
namespace.

Signed-off-by: Matt Klich <matt@elementalvoid.com>

* bump version

Signed-off-by: David J. M. Karlsen <david@davidkarlsen.com>
2019-12-16 19:01:39 -08:00
Lénaïc Huard c65adfb0b7 [stable/datadog] Allow dots in cluster names (#19618)
* [stable/datadog] Allow dots in cluster names

because some users already have dots in their cluster names:
https://github.com/helm/charts/pull/19327#issuecomment-565535449

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>

* [stable/datadog] Add a test for clusterName

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
2019-12-16 09:27:37 -08:00
Lénaïc Huard fbf05893a5 [stable/datadog] Add validity checks on clusterName (#19327)
The cluster name parameter has been introduced to disambiguate nodes
having the same name in different clusters.

Cluster names are, for ex., used to build hostnames and must therefore
comply with some rules.

We enforce here the same rules as the ones enforced by GKE:
https://cloud.google.com/kubernetes-engine/docs/reference/rest/v1beta1/projects.locations.clusters#Cluster.FIELDS.name

The DataDog agent itself is already checking the validity of cluster names since
DataDog/datadog-agent#4492.

The goal of this change in the helm chart is to catch issues as early as possible because
having a clear error message from helm is smarter than having to dig in the logs of
a failing agent.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
2019-12-13 09:25:08 -08:00
Lénaïc Huard b14d8fc983 [stable/datadog] Make the seccomp profile for system-probe optional (#19533)
* [stable/datadog] Remove the seccomp profile for system-probe

The `system-probe` container currently has a specific seccomp profile.
This seccomp profile currently misses some syscalls that are necessary to
exec inside the container.

Concretely, attempting to exec inside the container produces this error:

```
$ kubectl exec -ti datadog-fswnc -c system-probe /bin/bash
shell-init: error retrieving current directory: getcwd: cannot access parent directories: Operation not permitted
bash: initialize_job_control: getpgrp failed: Operation not permitted
command terminated with exit code 1
```

If we add `setpgrp` to the seccomp profile, we get:

```
$ kubectl exec -ti datadog-kbg97 -c system-probe /bin/bash
shell-init: error retrieving current directory: getcwd: cannot access parent directories: Operation not permitted
I have no name!@datadog-kbg97:.$ exit
```

If we add `getcwd`, we get:

```
$ kubectl exec -ti datadog-7b7lf -c system-probe /bin/bash
I have no name!@datadog-7b7lf:/$ exit
```

If we add `geteuid` and `geteuid32`, we get:

```
$ kubectl exec -ti datadog-c42rb -c system-probe /bin/bash
/bin/bash: cannot set uid to -1: effective uid 0: Invalid argument
/bin/bash: cannot set gid to -1: effective gid -1: Invalid argument
bash-5.0$ exit
```

If we get `getgid` and `getgid32`, we get:

```
$ kubectl exec -ti datadog-tp4qd -c system-probe /bin/bash
/bin/bash: cannot set uid to -1: effective uid 0: Invalid argument
bash-5.0$ exit
```

etc.

If we compare the seccomp profile of `system-probe` with the
[default one](https://github.com/moby/moby/blob/4b0371fb36a958589319ab7c501ff4bc22645cfa/profiles/seccomp/default.json),
we see that a lot of syscalls that are missing are innocuous (`getcwd`) or might become useful one day (`inotify` family)
Some syscalls are added on purpose for the `system-probe` container like `bpf` or `perf_event_open` ones.
But those syscalls are part of the [default seccomp profile for containers that have the `SYS_ADMIN` capability](https://github.com/moby/moby/blob/4b0371fb36a958589319ab7c501ff4bc22645cfa/profiles/seccomp/default.json#L567-L594),
and the [`system-probe` container do have the `SYS_ADMIN` capability](https://github.com/helm/charts/blob/3907cebc7042f452506a7471f912d6d0c8380e51/stable/datadog/templates/container-system-probe.yaml#L7).

So, the `system-probe` specific seccomp profile is not necessary to have the `system-probe` container able to load eBPF programs.

Its removal has been tested on GKE, both with Ubuntu and with Container-Optimized OS
and both with docker and containerd.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>

* Make the ad-hoc seccomp profile for system-probe an option

which is enabled by default to stick with the current behavior.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>

* [stable/datadog] Allow use of any arbitrary seccomp profile

…for system-probe.
By default, it will create an ad-hoc one.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>

* [stable/datadog] Add a CI test for seccomp profile override

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
2019-12-13 07:34:55 -08:00
Ivan Sukhomlyn ada60df1bd [stable/datadog] Add nodeSelector for Cluster Agent Deployment (#19430)
Signed-off-by: Ivan Sukhomlyn <ivan.sukhomlyn@ring.com>
2019-12-13 06:02:54 -08:00
Celene f2d2cb5523 [stable/datadog] add celenechang to datadog owners (#19515)
* add celenechang to datadog owners

Signed-off-by: Celene <celene@datadoghq.com>

* bump chart

Signed-off-by: Celene <celene@datadoghq.com>
2019-12-12 23:28:54 -08:00
Cedric Lamoriniere 52e585114f [stable/datadog] update docker images version (#19559)
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
2019-12-12 09:24:32 -08:00
Lénaïc Huard 739116b6f4 [stable/datadog] Fix passwd volume error when processAgentEnabled is unset (#18808)
When `processAgentEnabled` is not set, trying to instantiate the datadog chart caused the following error:

```
Error: release datadog failed: DaemonSet.apps "datadog" is invalid: spec.template.spec.containers[1].volumeMounts[2].name: Not found: "passwd"
```

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
2019-11-27 02:19:21 -08:00
shangwang 65f943cd19 [stable/datadog] add stat system call to system-probe seccomp profile (#19127)
* add stat system call to system-probe seccomp profile

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* bump chart version

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>
2019-11-25 15:07:12 -08:00
shangwang 3907cebc70 Add IPC_LOCK to system-probe container capabilities (#18599)
Signed-off-by: Shang Wang <shang.wang@datadoghq.com>
2019-11-25 08:29:25 -08:00
Lénaïc Huard 2a12337a3d [stable/datadog] Grant access to kubelet’s GET /stats/summary (#19047)
With DataDog/integrations-core#5052, the datadog agent starts monitoring
the `stats/summary/` endpoint of the kubelet.
So, we need to grant it a role that allows it.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
2019-11-22 04:45:28 -08:00
Lénaïc Huard b5ba0c631d [stable/datadog] Add Lénaïc Huard (L3n41c) to OWNERS (#18811)
Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
2019-11-12 05:44:06 -08:00
Doug WinterandCedric Lamoriniere 7ba8bec233 [stable/datadog] allow host networking for metrics (#15206)
* [stable/datadog] allow host networking for metrics

Signed-off-by: Doug Winter <doug.winter@isotoma.com>

* doc update

Signed-off-by: Doug Winter <doug.winter@isotoma.com>

* Update stable/datadog/templates/agent-service-metrics.yaml

Co-Authored-By: Cedric Lamoriniere <cedric.lamoriniere@datadoghq.com>
Signed-off-by: Doug Winter <doug.winter@isotoma.com>

* Update stable/datadog/values.yaml

Co-Authored-By: Cedric Lamoriniere <cedric.lamoriniere@datadoghq.com>
Signed-off-by: Doug Winter <doug.winter@isotoma.com>

* annotations is unused

Signed-off-by: Doug Winter <doug.winter@isotoma.com>

* Rework structure of values to match usage

Signed-off-by: Andrew Plummer <plummer574@gmail.com>

* Bump version

Signed-off-by: Andrew Plummer <plummer574@gmail.com>

* CR: remove docstring line

Signed-off-by: Andrew Plummer <plummer574@gmail.com>
2019-10-31 06:47:36 -07:00
Martin Gaida 685f43751e [stable/datadog] Allow custom agent configuration (#15861)
* datadog agent: allow custom configuration

Signed-off-by: Martin Gaida <mgaida@flipboard.com>
Signed-off-by: Martin Gaida <martin.m.gaida@gmail.com>

* datadog agent: configuration documentation

Signed-off-by: Martin Gaida <mgaida@flipboard.com>
Signed-off-by: Martin Gaida <martin.m.gaida@gmail.com>

* stable/datadog: bump version again

Signed-off-by: Martin Gaida <martin.m.gaida@gmail.com>

* stable/datadog: bump version

Signed-off-by: Martin Gaida <martin.m.gaida@gmail.com>
2019-10-08 13:19:49 -07:00
Stefan Sedich aa14832606 [stable/datadog] When using nonLocalTraffic=true also set DD_APM_NON_LOCAL_TRAFFIC (#17080)
Signed-off-by: Stefan Sedich <stefan.sedich@gmail.com>
2019-10-07 13:11:11 -07:00
Cedric Lamoriniere 47762ae799 [stable/datadog] Add labels + deprecation notice (#17455)
* [stable/datadog] Add labels recommended by Helm

See https://helm.sh/docs/chart_best_practices/#standard-labels

New labels are added, no existing labels are removed nor any label selectors updated.

Signed-off-by: Peter Rifel <pgrifel@gmail.com>

* [stable/datadog] Add additional deprecation notes.

* update recommended labels for improving the migration strategy.
* prepare the deployment agent configuration deprecation

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* [stable/datadog] add ci values.yaml files

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* add missing labels on system-probe resources

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* update NOTES.txt

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
2019-10-01 07:13:34 -07:00
shangwang 4539e30e62 [stable/datadog]add system-probe agent to datadog chart (#17376)
* [stable/datadog] add system-probe container to datadog-agent daemonset

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* [stable/datadog] some fixes

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* remove system-probe configmap

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* bring back the sysprobe config map

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* indentation

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* fix env var name

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* updated configs in values.yaml for more information

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* update how system-probe is run

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* bump chart version

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* bump chart again

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* hard code unix socket location

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* remove resource definition for init container

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* add labels

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* fix value syntax and move system-probe values to the same level with
datadog

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* remove unused setup

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* update README file

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* fix chart and update README

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* update system-probe container to work with dedicated container case

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* bump chart version

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* bump chart version

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* remove resources config for systemProbe

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* fix process-agent resource indent

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* use the same format for volumes

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* update README

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* allow empty initContainers section

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* bump chart with minor version

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* make seccomp root directory be configurable via values

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* Update README for processAgentEanbled 3 states

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* update daemonset and README to make sure system-probe is only enabled if
both daemonset.useDedicatedContainers and systemProbe.enabled are true

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* update README to reflect the fact that system-probe needs flag
useDedicatedContainers

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* rename system-probe template

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* don't show empty initContainers when not using dedicated containers

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* make bpfDebug flag required and default be false

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* reduce seccomp profile

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* refine seccomp

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* Revert "refine seccomp"

This reverts commit a4cc7e667cd2118a2b8bd1b07444a3f93bb539c8.

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* Revert "reduce seccomp profile"

This reverts commit 02b18c16aadfc56354f396757f3bbde4c3d6c9f8.

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* better seccomp

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>

* add config for apparmor

Signed-off-by: Shang Wang <shang.wang@datadoghq.com>
2019-09-25 06:30:00 -07:00
Cedric Lamoriniere 2704ccf3aa Support apps/v1 apigroup for Daemonset and deployment (#17397)
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
2019-09-24 10:31:28 -07:00
Javi Polo 3ff7c31fb4 [stable/datadog] Add possibility to extract node labels as metric tags (#17184)
Signed-off-by: Javi Polo <javipolo@drslump.org>
2019-09-17 13:11:15 -07:00
Ahmed Mezghani b87b93fc69 [stable/datadog] Make deployment strategies configurable (#17165)
* update readme

Signed-off-by: Ahmed Mezghani <ahmed.mezghani@outlook.com>

* update default strategies

Signed-off-by: Ahmed Mezghani <ahmed.mezghani@outlook.com>

* update readme + maxUnavailable

Signed-off-by: Ahmed Mezghani <ahmed.mezghani@outlook.com>

* quotes

Signed-off-by: Ahmed Mezghani <ahmed.mezghani@outlook.com>
2019-09-17 08:12:24 -07:00
Cedric Lamoriniere d4ffe43751 [stable/datadog] Update application version to 6.13.0 and ksm to 1.7.2 (#16267)
* Update stable/datadog application to 6.13.0

* Bump the chart version to `1.33.0`
* Update the application version to `6.13.0`
* Update Kube-State-Metrics version to `1.7.2` with chart `2.2.3`
* Fix wrong indentation in kube-state-metrics parameters
* Document the possibility to overwrite KSM container resources
* Add ci/*-values.yaml files for CI validation

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* temporary remove stable/datadog/ci folder

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>

* add in comment example

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
2019-08-16 11:20:10 -07:00
farshad-hobsons 8f3e5889dd [stable/datadog] Add an option to reference an existing clusterAgent.token (#16208)
* [stable/datadog]: adding option to pass existing ClusterAgent token secret

Signed-off-by: Fahad Arshad <fahad.arshad@hobsons.com>

* [stable/datadog]: Chart version bump

Signed-off-by: Fahad Arshad <fahad.arshad@hobsons.com>

* [stable/datadog]: adding an extra line in agent-secret.yaml

Signed-off-by: Fahad Arshad <fahad.arshad@hobsons.com>

* use clusterAgent.tokenSecretName template to make code DRY

Signed-off-by: Fahad Arshad <fahad.arshad@hobsons.com>
2019-08-13 04:29:41 -07:00
Joe Hohertz 6c5a877928 allow setting tolerations for clusterchecks (#15624)
Signed-off-by: Joe Hohertz <joe@viafoura.com>
2019-07-30 07:38:51 -07:00
Cedric Lamoriniere a944a6ebaf [stable/datadog] Fix several aspect of KSM integration (#15908)
* [stable/datadog] Fix error in readme configuration parameter
* Fixes #15526. `rbac.serviceAccount` should be `rbac.serviceAccountName` in configuration parameter table
* Update kube-state-metrics deps to 2.0.0
* bump stable/datadog chart to 1.32.0

Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
2019-07-30 06:26:51 -07:00
Cedric Lamoriniere 93deeee48a [stable/datadog] update default image versions (#15520)
Signed-off-by: cedric lamoriniere <cedric.lamoriniere@datadoghq.com>
2019-07-26 01:25:58 -07:00
Xavier Lucas 31462f6be2 [stable/datadog] Add xlucas to OWNERS (#15585)
* Add xlucas to OWNERS

Signed-off-by: Xavier Lucas <xavier.lucas@datadoghq.com>

* Update chart version

Signed-off-by: Xavier Lucas <xavier.lucas@datadoghq.com>
2019-07-17 02:40:34 -07:00
Steve Huff 2af95ff410 [stable/datadog] Fix whitespace trimming (#15577)
Using double-sided whitespace trimming (something like `{{- end -}}` can be
dangerous anywhere other than at the very beginning and the very end of a
template file, because it trims carriage returns.  This makes it possible to
inadvertently create a manifest like the following:

```yaml
apiVersion: "rbac.authorization.k8s.io/v1"
kind: ClusterRoleBinding
metadata:
  labels:
    app: "datadog"
    chart: "datadog-1.31.8"
    release: "datadog"
    heritage: "Tiller"
  name: datadog
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: datadog
subjects:
  - kind: ServiceAccount
    name: datadog
    namespace: datadog---
apiVersion: v1
kind: ServiceAccount
metadata:
  labels:
    app: "datadog"
    chart: "datadog-1.31.8"
    heritage: "Tiller"
    release: "datadog"
  name: datadog
---
```

Signed-off-by: Steve Huff <shuff@vecna.org>
2019-07-17 01:59:35 -07:00
Ahmed Mezghani 27bba5796f fix yamls (#15534)
Signed-off-by: Ahmed Mezghani <ahmed.mezghani@outlook.com>
2019-07-15 06:59:07 -07:00
Dennis Webb 96a0359aaa [stable/datadog] Adds podAnnotations to cluster-agent deployment (#15384)
Signed-off-by: Dennis Webb <dennis@bluesentryit.com>
2019-07-15 02:05:07 -07:00
Joe Hohertz fc0f5a865a [stable/datadog] ensure init scripts run in correct order (#15463)
* ensure init scripts run in correct order

Signed-off-by: Joe Hohertz <joe@viafoura.com>

* re-bump chart version

Signed-off-by: Joe Hohertz <joe@viafoura.com>
2019-07-12 12:47:06 -07:00
Ahmed Mezghani 81405b0a33 [stable/datadog] Regroup template yaml files (#15371)
* regroup template yaml files

Signed-off-by: Ahmed Mezghani <ahmed.mezghani@outlook.com>

* bump version

Signed-off-by: Ahmed Mezghani <ahmed.mezghani@outlook.com>

* regroup hpa rbac

Signed-off-by: Ahmed Mezghani <ahmed.mezghani@outlook.com>
2019-07-11 11:21:08 -07:00
Peter Rifel f8500ca19d [stable/datadog] Add priorityClassName to Cluster Agent deployment (#15135)
Signed-off-by: Peter Rifel <pgrifel@gmail.com>
2019-07-02 09:47:09 -07:00
Yuya Takeyama 220d820cc6 [stable/datadog] Make name of dogstatsd socket configurable (#14898)
* Make DogStatsD socket path configurable

Signed-off-by: Yuya Takeyama <sign.of.the.wolf.pentagram@gmail.com>

* Describe about `datadog.dogStatsDSocketPath`

Signed-off-by: Yuya Takeyama <sign.of.the.wolf.pentagram@gmail.com>

* Bump version

Signed-off-by: Yuya Takeyama <sign.of.the.wolf.pentagram@gmail.com>

* Refine README.md for `datadog.dogStatsDSocketPath`

Signed-off-by: Yuya Takeyama <sign.of.the.wolf.pentagram@gmail.com>
2019-07-01 07:49:21 -07:00
Yuya Takeyama c492a519b3 [stable/datadog] Fix wrong indentations (#14894)
* Fix wrong indentations

Signed-off-by: Yuya Takeyama <sign.of.the.wolf.pentagram@gmail.com>

* Bump chart version

Signed-off-by: Yuya Takeyama <sign.of.the.wolf.pentagram@gmail.com>

* Fix more indentations

Signed-off-by: Yuya Takeyama <sign.of.the.wolf.pentagram@gmail.com>

* Fix more indentations

Signed-off-by: Yuya Takeyama <sign.of.the.wolf.pentagram@gmail.com>
2019-06-19 08:28:57 -07:00