diff --git a/Dockerfile b/Dockerfile index 014e303..b958300 100644 --- a/Dockerfile +++ b/Dockerfile @@ -35,6 +35,8 @@ COPY ./js-web/KubeInvaders /var/www/html RUN sed -i.bak 's/listen\(.*\)80;/listen 8081;/' /etc/nginx/conf.d/default.conf COPY nginx/nginx.conf /etc/nginx/nginx.conf +COPY nginx/metrics.lua /tmp/metrics.lua + COPY nginx/KubeInvaders.templ /etc/nginx/conf.d/KubeInvaders.templ COPY nginx/KubeInvaders_dev.templ /etc/nginx/conf.d/KubeInvaders_dev.templ diff --git a/README.md b/README.md index 956d043..6c44b81 100644 --- a/README.md +++ b/README.md @@ -9,8 +9,9 @@ 1. [Description](#Description) 2. [Special Input Keys and features](#Special-Input-Keys-and-features) 3. [Installation](#Installation) -4. [Notes for large clusters](#Notes-for-large-clusters) -5. [Configuration](#Configuration) +4. [Prometheus Metrics - Make sense of Kubeinvaders!](#Metrics) +5. [Notes for large clusters](#Notes-for-large-clusters) +6. [Configuration](#Configuration) ## Description @@ -135,9 +136,17 @@ For clusters with many workers-nodes, KubeInvaders selects a subset of random it | Item | Max Number | |-----------|--------------| | Nodes | 15 | +## Metrics + +KubeInvaders exposes metrics for Prometheus through the standard endpoint /metrics + +In order to use metrics functions install Redis into the namespace of Kubeinvaders + +```bash +helm install redis bitnami/redis -n kubeinvaders -f redis/values.yaml +``` ## Configuration - ### Environment Variables - Make the game more difficult to win! Set the following variables in Kubernetes Deployment or OpenShift DeploymentConfig: diff --git a/deploy_kubeinvaders.sh b/deploy_kubeinvaders.sh deleted file mode 100644 index 948a610..0000000 --- a/deploy_kubeinvaders.sh +++ /dev/null @@ -1,17 +0,0 @@ -#Change with the namespace you want to stress -TARGET_NAMESPACE='foobar' - -#Change with the URL of your Kubeinvaders -ROUTE_HOST=kubeinvaders.org - -kubectl apply -f kubernetes/kubeinvaders-namespace.yml -kubectl apply -f kubernetes/kubeinvaders-deployment.yml -n kubeinvaders -kubectl expose deployment kubeinvaders --type=NodePort --name=kubeinvaders -n kubeinvaders --port 8080 -kubectl apply -f kubernetes/kubeinvaders-ingress.yml -n kubeinvaders -kubectl create sa kubeinvaders -n $TARGET_NAMESPACE -kubectl apply -f kubernetes/kubeinvaders-role.yml -kubectl apply -f kubernetes/kubeinvaders-rolebinding.yml -TOKEN=`kubectl describe secret $(kubectl get secret -n $TARGET_NAMESPACE | grep 'kubeinvaders-token' | awk '{ print $1}') -n $TARGET_NAMESPACE | grep 'token:' | awk '{ print $2}'` -kubectl set env deployment/kubeinvaders TOKEN=$TOKEN -n kubeinvaders -kubectl set env deployment/kubeinvaders NAMESPACE=$TARGET_NAMESPACE -n kubeinvaders -kubectl set env deployment/kubeinvaders ROUTE_HOST=$ROUTE_HOST -n kubeinvaders diff --git a/main/mymodules/node.lua b/main/mymodules/node.lua index 4ac8555..74155e1 100644 --- a/main/mymodules/node.lua +++ b/main/mymodules/node.lua @@ -53,7 +53,7 @@ function M.http_get_nodes_result(self, _, response) local pos_x = 300 local pos_y = 500 local nodes_cnt = 1 - + local master = false print("Get nodes output") print('/api/v1/nodes response: ' .. response.status) print("Node table size: " .. node_items_size) @@ -62,7 +62,15 @@ function M.http_get_nodes_result(self, _, response) for k, v in pairs(node_items) do for k1, v2 in pairs(v) do if v2["name"] then - table.insert(kubernetes_nodes_temp,{ name = v2["name"], id = '' }) + for k3, v3 in pairs(v2["labels"]) do + if k3 == "node-role.kubernetes.io/master" then + master = true + end + end + if not master then + table.insert(kubernetes_nodes_temp,{ name = v2["name"], id = '' }) + end + master = false end end end diff --git a/main/mymodules/spaceship.lua b/main/mymodules/spaceship.lua index af63625..4b318c7 100644 --- a/main/mymodules/spaceship.lua +++ b/main/mymodules/spaceship.lua @@ -6,23 +6,35 @@ local M = {} function M.auto() - msg.post("ui#gui", "error",{ errormessage = "" }) - math.randomseed(os.clock()*100000000000) - rand_pos = math.random(300, 1500) - pos = go.get_position() + local pos = go.get_position() + local cnt = 0 + + --msg.post("ui#gui", "error",{ errormessage = "" }) + --math.randomseed(os.clock()*100000000000) pos.y = 300 - go.set_position(pos) - - pos.x = rand_pos - + go.set_position(pos) + + pos.x = automatic_pilot_x + go.animate(go.get_id(), "position.x", go.PLAYBACK_ONCE_FORWARD, pos.x, go.EASING_LINEAR, 0.5, 0, function() pos = go.get_position() bullet = factory.create("/bullet#bulletfactory", pos) - go.animate(bullet, "position.y", go.PLAYBACK_ONCE_FORWARD, 1200, go.EASING_LINEAR, 1, 0, function() + go.animate(bullet, "position.y", go.PLAYBACK_ONCE_FORWARD, 1200, go.EASING_LINEAR, 1, 0, function() go.delete(bullet) end) end) + if not automatic_pilot_x_reverse then + automatic_pilot_x = automatic_pilot_x + 100 + else + automatic_pilot_x = automatic_pilot_x - 100 + end + + if automatic_pilot_x > automatic_pilot_x_limit then + automatic_pilot_x_reverse = true + elseif automatic_pilot_x < automatic_pilot_x_start then + automatic_pilot_x_reverse = false + end end return M \ No newline at end of file diff --git a/main/spaceship.script b/main/spaceship.script index 43d971a..cc72678 100644 --- a/main/spaceship.script +++ b/main/spaceship.script @@ -98,6 +98,18 @@ latest_kubernetes_nodes_request_show = 0 -- max number of nodes to show max_nodes = 15 +-- put the spaceship in automatic_pilot_x when automatic pilot is activated +automatic_pilot_x = 400 + +-- max x when automatic pilot is activated +automatic_pilot_x_limit = 1400 + +-- min x when automatic pilot is activated +automatic_pilot_x_start= 400 + +-- used for change direction of the spaceship +automatic_pilot_x_reverse = false + local COLLISION_RESPONSE = hash("collision_response") local timer = require "main.mymodules.timer" local spaceship = require "main.mymodules.spaceship" @@ -205,13 +217,21 @@ function start_chaos() msg.post("ui#gui", "error1",{ errormessage = "" }) end end) - timer.repeat_seconds(1, function() + timer.repeat_seconds(0.5, function() if automatic then spaceship.auto() math.randomseed(os.clock()*100000000000) - if math.random(1, 100) % 3 == 0 then + local math_rand = math.random(1, 100) + if math_rand % 3 == 0 then k8s_node.get_nodes() end + if math_rand % 5 == 0 then + if automatic_pilot_x_reverse then + automatic_pilot_x_reverse = false + else + automatic_pilot_x_reverse = true + end + end end end) pod_api.set_pods() @@ -243,25 +263,25 @@ function on_input(self, action_id, action) p = go.get_position() if action_id == hash("up") then if p.y < 1000 then - p.y = p.y + 4 + p.y = p.y + 5 go.set_position(p) end elseif action_id == hash("down") then if p.y > 1 then - p.y = p.y - 4 + p.y = p.y - 5 go.set_position(p) end elseif action_id == hash("left") then if p.x > 1 then - p.x = p.x - 4 + p.x = p.x - 5 go.set_position(p) end elseif action_id == hash("right") then if p.x < 1800 then - p.x = p.x + 4 + p.x = p.x + 5 go.set_position(p) end @@ -398,8 +418,6 @@ function on_message(self, message_id, message, sender) end if message_id == COLLISION_RESPONSE and started_chaos and not last_pod_log then - - print("log1!") msg.post("ui#gui","pod_log") for i,value in ipairs(current_pods) do diff --git a/nginx/KubeInvaders.templ b/nginx/KubeInvaders.templ index 324b3b8..c2f7ee0 100644 --- a/nginx/KubeInvaders.templ +++ b/nginx/KubeInvaders.templ @@ -3,6 +3,19 @@ server { root /var/www/html/; index index.html; + location /metrics { + default_type text/html; + content_by_lua_block { + local redis = require "resty.redis" + local red = redis:new() + local okredis, errredis = red:connect(os.getenv("REDIS_URL"), 6379) + for i, res in ipairs(red:keys("*")) do + ngx.log(ngx.ERR, res) + ngx.say(res .. " " .. red:get(res)) + end + } + } + location /kube/kube-linter { default_type text/html; content_by_lua_block { @@ -17,6 +30,7 @@ server { location /kube/chaos-node { default_type text/html; + access_by_lua_file /tmp/metrics.lua; content_by_lua_block { local arg = ngx.req.get_uri_args() ngx.req.read_body() @@ -26,23 +40,15 @@ server { } } - location / { - try_files $uri $uri/ =404; - add_header Last-Modified $date_gmt; - add_header Cache-Control 'no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0'; - if_modified_since off; - expires off; - etag off; - } - location /kube { rewrite ^/kube(.*)$ /api$1 break; proxy_pass https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS}; + access_by_lua_file /tmp/metrics.lua; } location /kube/api { rewrite ^/kube/api(.*)$ /api$1 break; proxy_pass https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS}; + access_by_lua_file /tmp/metrics.lua; } - } diff --git a/nginx/KubeInvaders_dev.templ b/nginx/KubeInvaders_dev.templ index f2e7856..7f286b6 100644 --- a/nginx/KubeInvaders_dev.templ +++ b/nginx/KubeInvaders_dev.templ @@ -2,6 +2,19 @@ server { listen 8080 default_server; root /var/www/html/; index index.html; + + location /metrics { + default_type text/html; + content_by_lua_block { + local redis = require "resty.redis" + local red = redis:new() + local okredis, errredis = red:connect(os.getenv("REDIS_URL"), 6379) + for i, res in ipairs(red:keys("*")) do + ngx.log(ngx.ERR, res) + ngx.say(res .. " " .. red:get(res)) + end + } + } location /kube/kube-linter { default_type text/html; @@ -17,6 +30,8 @@ server { location /kube/chaos-node { default_type text/html; + access_by_lua_file /tmp/metrics.lua; + content_by_lua_block { local arg = ngx.req.get_uri_args() ngx.req.read_body() @@ -26,23 +41,15 @@ server { } } - location / { - try_files $uri $uri/ =404; - add_header Last-Modified $date_gmt; - add_header Cache-Control 'no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0'; - if_modified_since off; - expires off; - etag off; - } - location /kube { - rewrite ^/kube(.*)$ /api$1 break; - proxy_pass ${ENDPOINT}; + rewrite ^/kube(.*)$ /api$1 break; + proxy_pass ${ENDPOINT}; + access_by_lua_file /tmp/metrics.lua; } location /kube/api { - rewrite ^/kube/api(.*)$ /api$1 break; - proxy_pass ${ENDPOINT}; + rewrite ^/kube/api(.*)$ /api$1 break; + proxy_pass ${ENDPOINT}; + access_by_lua_file /tmp/metrics.lua; } - } diff --git a/nginx/metrics.lua b/nginx/metrics.lua new file mode 100644 index 0000000..7ab6c8c --- /dev/null +++ b/nginx/metrics.lua @@ -0,0 +1,69 @@ +local redis = require "resty.redis" +local red = redis:new() +local okredis, errredis = red:connect(os.getenv("REDIS_URL"), 6379) +local arg = ngx.req.get_uri_args() +local incr = 0 +if okredis then + if ngx.var.request_method == "DELETE" then + ngx.log(ngx.ERR, "Connection to Redis is ok") + + -- Count the total of deleted pods + local res, err = red:get("deleted_pods_total") + if res == ngx.null then + ngx.say(err) + red:set("deleted_pods_total", 1) + else + incr = res + 1 + red:set("deleted_pods_total", incr) + end + + -- TODO: Make a better regular expression! + local namespace_pods = string.match(ngx.var.request_uri, '^.*/namespaces/(.*)/.*$') + local namespace = namespace_pods:gsub("/pods", "") + + -- Count the total of deleted pods for namespace + local res, err = red:get("deleted_pods_total_on_" .. namespace) + if res == ngx.null then + red:set("deleted_pods_total_on_" .. namespace, 1) + else + incr = res + 1 + red:set("deleted_pods_total_on_" .. namespace, incr) + end + + + elseif ngx.var.request_method == "GET" and string.match(ngx.var.request_uri, "^.*/chaos[-]node.*$") then + ngx.log(ngx.ERR, "Chaos node action has been detected") + + -- Count the total of chaos jobs launched against nodes + local chaos_node_res, err = red:get("chaos_node_jobs_total") + if chaos_node_res == ngx.null then + ngx.say(err) + red:set("chaos_node_jobs_total", 0) + else + local incr = chaos_node_res + 1 + local res, err = red:set("chaos_node_jobs_total",incr) + end + + -- Count the total of chaos jobs launched against nodes per node + local node_name = arg['node_name'] + local chaos_node_res, err = red:get("chaos_node_jobs_total_on_" .. node_name) + if chaos_node_res == ngx.null then + ngx.say(err) + red:set("chaos_node_jobs_total_on_" .. node_name, 1) + else + local incr = chaos_node_res + 1 + local res, err = red:set("chaos_node_jobs_total_on_" .. node_name,incr) + end + end + + elseif ngx.var.request_method == "GET" and ngx.var.request_uri == "/metrics" then + for i, res in ipairs(red:keys("*")) do + ngx.log(ngx.ERR, res) + ngx.say(res .. " " .. red:get(res)) + end + +else + ngx.log(ngx.ERR, "Connection to Redis is not ok. REDIS_URL is " .. os.getenv("REDIS_URL")) + ngx.log(ngx.ERR, errredis) + +end diff --git a/nginx/nginx.conf b/nginx/nginx.conf index 551a02e..9fec909 100644 --- a/nginx/nginx.conf +++ b/nginx/nginx.conf @@ -1,6 +1,7 @@ worker_processes 2; error_log /var/log/nginx/error.log warn; pid /var/run/nginx.pid; +env REDIS_URL; events { worker_connections 1024; diff --git a/redis/values.yaml b/redis/values.yaml new file mode 100644 index 0000000..1b5c98a --- /dev/null +++ b/redis/values.yaml @@ -0,0 +1,808 @@ +## Global Docker image parameters +## Please, note that this will override the image parameters, including dependencies, configured to use the global value +## Current available global Docker image parameters: imageRegistry and imagePullSecrets +## +global: + # imageRegistry: myRegistryName + # imagePullSecrets: + # - myRegistryKeySecretName + # storageClass: myStorageClass + redis: {} + +## Bitnami Redis image version +## ref: https://hub.docker.com/r/bitnami/redis/tags/ +## +image: + registry: docker.io + repository: bitnami/redis + ## Bitnami Redis image tag + ## ref: https://github.com/bitnami/bitnami-docker-redis#supported-tags-and-respective-dockerfile-links + ## + tag: 6.0.9-debian-10-r38 + ## Specify a imagePullPolicy + ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' + ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images + ## + pullPolicy: IfNotPresent + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## + # pullSecrets: + # - myRegistryKeySecretName + +## String to partially override redis.fullname template (will maintain the release name) +## +# nameOverride: + +## String to fully override redis.fullname template +## +# fullnameOverride: + +## Cluster settings +cluster: + enabled: false + slaveCount: 3 + +## Use redis sentinel in the redis pod. This will disable the master and slave services and +## create one redis service with ports to the sentinel and the redis instances +sentinel: + enabled: false + ## Require password authentication on the sentinel itself + ## ref: https://redis.io/topics/sentinel + usePassword: true + ## Bitnami Redis Sentintel image version + ## ref: https://hub.docker.com/r/bitnami/redis-sentinel/tags/ + ## + image: + registry: docker.io + repository: bitnami/redis-sentinel + ## Bitnami Redis image tag + ## ref: https://github.com/bitnami/bitnami-docker-redis-sentinel#supported-tags-and-respective-dockerfile-links + ## + tag: 6.0.9-debian-10-r38 + ## Specify a imagePullPolicy + ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' + ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images + ## + pullPolicy: IfNotPresent + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## + # pullSecrets: + # - myRegistryKeySecretName + masterSet: mymaster + initialCheckTimeout: 5 + quorum: 2 + downAfterMilliseconds: 60000 + failoverTimeout: 18000 + parallelSyncs: 1 + port: 26379 + ## Additional Redis configuration for the sentinel nodes + ## ref: https://redis.io/topics/config + ## + configmap: + ## Enable or disable static sentinel IDs for each replicas + ## If disabled each sentinel will generate a random id at startup + ## If enabled, each replicas will have a constant ID on each start-up + ## + staticID: false + ## Configure extra options for Redis Sentinel liveness and readiness probes + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) + ## + livenessProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 5 + timeoutSeconds: 5 + successThreshold: 1 + failureThreshold: 5 + readinessProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 5 + timeoutSeconds: 1 + successThreshold: 1 + failureThreshold: 5 + customLivenessProbe: {} + customReadinessProbe: {} + ## Redis Sentinel resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + # resources: + # requests: + # memory: 256Mi + # cpu: 100m + ## Redis Sentinel Service properties + service: + ## Redis Sentinel Service type + type: ClusterIP + sentinelPort: 26379 + redisPort: 6379 + + ## Specify the nodePort value for the LoadBalancer and NodePort service types. + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport + ## + # sentinelNodePort: + # redisNodePort: + + ## Provide any additional annotations which may be required. This can be used to + ## set the LoadBalancer service type to internal only. + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + ## + annotations: {} + labels: {} + loadBalancerIP: + +## Specifies the Kubernetes Cluster's Domain Name. +## +clusterDomain: cluster.local + +networkPolicy: + ## Specifies whether a NetworkPolicy should be created + ## + enabled: true + + ## The Policy model to apply. When set to false, only pods with the correct + ## client label will have network access to the port Redis is listening + ## on. When true, Redis will accept connections from any source + ## (with the correct destination port). + ## + # allowExternal: true + + ## Allow connections from other namespaces. Just set label for namespace and set label for pods (optional). + ## + ingressNSMatchLabels: {} + ingressNSPodMatchLabels: {} + +serviceAccount: + ## Specifies whether a ServiceAccount should be created + ## + create: false + ## The name of the ServiceAccount to use. + ## If not set and create is true, a name is generated using the fullname template + name: + ## Add annotations to service account + # annotations: + # iam.gke.io/gcp-service-account: "sa@project.iam.gserviceaccount.com" + +rbac: + ## Specifies whether RBAC resources should be created + ## + create: false + + role: + ## Rules to create. It follows the role specification + # rules: + # - apiGroups: + # - extensions + # resources: + # - podsecuritypolicies + # verbs: + # - use + # resourceNames: + # - gce.unprivileged + rules: [] + +## Redis pod Security Context +securityContext: + enabled: true + fsGroup: 1001 + ## sysctl settings for master and slave pods + ## + ## Uncomment the setting below to increase the net.core.somaxconn value + ## + # sysctls: + # - name: net.core.somaxconn + # value: "10000" + +## Container Security Context +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ +## +containerSecurityContext: + enabled: true + runAsUser: 1001 + +## Use password authentication +usePassword: false +## Redis password (both master and slave) +## Defaults to a random 10-character alphanumeric string if not set and usePassword is true +## ref: https://github.com/bitnami/bitnami-docker-redis#setting-the-server-password-on-first-run +## +password: +## Use existing secret (ignores previous password) +# existingSecret: +## Password key to be retrieved from Redis secret +## +# existingSecretPasswordKey: + +## Mount secrets as files instead of environment variables +usePasswordFile: false + +## Persist data to a persistent volume (Redis Master) +persistence: + ## A manually managed Persistent Volume and Claim + ## Requires persistence.enabled: true + ## If defined, PVC must be created manually before volume will be bound + existingClaim: + +# Redis port +redisPort: 6379 + +## +## TLS configuration +## +tls: + # Enable TLS traffic + enabled: false + # + # Whether to require clients to authenticate or not. + authClients: true + # + # Name of the Secret that contains the certificates + certificatesSecret: + # + # Certificate filename + certFilename: + # + # Certificate Key filename + certKeyFilename: + # + # CA Certificate filename + certCAFilename: + # + # File containing DH params (in order to support DH based ciphers) + # dhParamsFilename: + +## +## Redis Master parameters +## +master: + ## Redis command arguments + ## + ## Can be used to specify command line arguments, for example: + ## Note `exec` is prepended to command + ## + command: "/run.sh" + ## Additional commands to run prior to starting Redis + ## + preExecCmds: "" + ## Additional Redis configuration for the master nodes + ## ref: https://redis.io/topics/config + ## + configmap: + ## Redis additional command line flags + ## + ## Can be used to specify command line flags, for example: + ## extraFlags: + ## - "--maxmemory-policy volatile-ttl" + ## - "--repl-backlog-size 1024mb" + extraFlags: [] + ## Comma-separated list of Redis commands to disable + ## + ## Can be used to disable Redis commands for security reasons. + ## Commands will be completely disabled by renaming each to an empty string. + ## ref: https://redis.io/topics/security#disabling-of-specific-commands + ## + disableCommands: + - FLUSHDB + - FLUSHALL + + ## Redis Master additional pod labels and annotations + ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ + podLabels: {} + podAnnotations: {} + + ## Redis Master resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + # resources: + # requests: + # memory: 256Mi + # cpu: 100m + ## Use an alternate scheduler, e.g. "stork". + ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ + ## + # schedulerName: + + # Enable shared process namespace in a pod. + # If set to false (default), each container will run in separate namespace, redis will have PID=1. + # If set to true, the /pause will run as init process and will reap any zombie PIDs, + # for example, generated by a custom exec probe running longer than a probe timeoutSeconds. + # Enable this only if customLivenessProbe or customReadinessProbe is used and zombie PIDs are accumulating. + # Ref: https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/ + shareProcessNamespace: false + ## Configure extra options for Redis Master liveness and readiness probes + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) + ## + livenessProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 5 + timeoutSeconds: 5 + successThreshold: 1 + failureThreshold: 5 + readinessProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 5 + timeoutSeconds: 1 + successThreshold: 1 + failureThreshold: 5 + + ## Configure custom probes for images other images like + ## rhscl/redis-32-rhel7 rhscl/redis-5-rhel7 + ## Only used if readinessProbe.enabled: false / livenessProbe.enabled: false + ## + # customLivenessProbe: + # tcpSocket: + # port: 6379 + # initialDelaySeconds: 10 + # periodSeconds: 5 + # customReadinessProbe: + # initialDelaySeconds: 30 + # periodSeconds: 10 + # timeoutSeconds: 5 + # exec: + # command: + # - "container-entrypoint" + # - "bash" + # - "-c" + # - "redis-cli set liveness-probe \"`date`\" | grep OK" + customLivenessProbe: {} + customReadinessProbe: {} + + ## Redis Master Node selectors and tolerations for pod assignment + ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector + ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#taints-and-tolerations-beta-feature + ## + # nodeSelector: {"beta.kubernetes.io/arch": "amd64"} + # tolerations: [] + ## Redis Master pod/node affinity/anti-affinity + ## + affinity: {} + + ## Redis Master Service properties + service: + ## Redis Master Service type + type: ClusterIP + port: 6379 + + ## Specify the nodePort value for the LoadBalancer and NodePort service types. + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport + ## + # nodePort: + + ## Provide any additional annotations which may be required. This can be used to + ## set the LoadBalancer service type to internal only. + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + ## + annotations: {} + labels: {} + loadBalancerIP: + # loadBalancerSourceRanges: ["10.0.0.0/8"] + + ## Enable persistence using Persistent Volume Claims + ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ + ## + persistence: + enabled: true + ## The path the volume will be mounted at, useful when using different + ## Redis images. + path: /data + ## The subdirectory of the volume to mount to, useful in dev environments + ## and one PV for multiple services. + subPath: "" + ## redis data Persistent Volume Storage Class + ## If defined, storageClassName: + ## If set to "-", storageClassName: "", which disables dynamic provisioning + ## If undefined (the default) or set to null, no storageClassName spec is + ## set, choosing the default provisioner. (gp2 on AWS, standard on + ## GKE, AWS & OpenStack) + ## + # storageClass: "-" + accessModes: + - ReadWriteOnce + size: 8Gi + ## Persistent Volume selectors + ## https://kubernetes.io/docs/concepts/storage/persistent-volumes/#selector + matchLabels: {} + matchExpressions: {} + + ## Update strategy, can be set to RollingUpdate or onDelete by default. + ## https://kubernetes.io/docs/tutorials/stateful-application/basic-stateful-set/#updating-statefulsets + statefulset: + labels: {} + annotations: {} + updateStrategy: RollingUpdate + ## Partition update strategy + ## https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#partitions + # rollingUpdatePartition: + + ## Redis Master pod priorityClassName + ## + priorityClassName: '' + + ## An array to add extra env vars + ## For example: + ## extraEnvVars: + ## - name: name + ## value: value + ## - name: other_name + ## valueFrom: + ## fieldRef: + ## fieldPath: fieldPath + ## + extraEnvVars: [] + + ## ConfigMap with extra env vars: + ## + extraEnvVarsCM: [] + + ## Secret with extra env vars: + ## + extraEnvVarsSecret: [] + +## +## Redis Slave properties +## Note: service.type is a mandatory parameter +## The rest of the parameters are either optional or, if undefined, will inherit those declared in Redis Master +## +slave: + ## Slave Service properties + service: + ## Redis Slave Service type + type: ClusterIP + ## Redis port + port: 6379 + ## Specify the nodePort value for the LoadBalancer and NodePort service types. + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport + ## + # nodePort: + + ## Provide any additional annotations which may be required. This can be used to + ## set the LoadBalancer service type to internal only. + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + ## + annotations: {} + labels: {} + loadBalancerIP: + # loadBalancerSourceRanges: ["10.0.0.0/8"] + + ## Redis slave port + port: 6379 + ## Can be used to specify command line arguments, for example: + ## Note `exec` is prepended to command + ## + command: "/run.sh" + ## Additional commands to run prior to starting Redis + ## + preExecCmds: "" + ## Additional Redis configuration for the slave nodes + ## ref: https://redis.io/topics/config + ## + configmap: + ## Redis extra flags + extraFlags: [] + ## List of Redis commands to disable + disableCommands: + - FLUSHDB + - FLUSHALL + + ## Redis Slave pod/node affinity/anti-affinity + ## + affinity: {} + + ## Kubernetes Spread Constraints for pod assignment + ## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/ + ## + # - maxSkew: 1 + # topologyKey: node + # whenUnsatisfiable: DoNotSchedule + spreadConstraints: {} + + # Enable shared process namespace in a pod. + # If set to false (default), each container will run in separate namespace, redis will have PID=1. + # If set to true, the /pause will run as init process and will reap any zombie PIDs, + # for example, generated by a custom exec probe running longer than a probe timeoutSeconds. + # Enable this only if customLivenessProbe or customReadinessProbe is used and zombie PIDs are accumulating. + # Ref: https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/ + shareProcessNamespace: false + ## Configure extra options for Redis Slave liveness and readiness probes + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) + ## + livenessProbe: + enabled: true + initialDelaySeconds: 30 + periodSeconds: 10 + timeoutSeconds: 5 + successThreshold: 1 + failureThreshold: 5 + readinessProbe: + enabled: true + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 10 + successThreshold: 1 + failureThreshold: 5 + + ## Configure custom probes for images other images like + ## rhscl/redis-32-rhel7 rhscl/redis-5-rhel7 + ## Only used if readinessProbe.enabled: false / livenessProbe.enabled: false + ## + # customLivenessProbe: + # tcpSocket: + # port: 6379 + # initialDelaySeconds: 10 + # periodSeconds: 5 + # customReadinessProbe: + # initialDelaySeconds: 30 + # periodSeconds: 10 + # timeoutSeconds: 5 + # exec: + # command: + # - "container-entrypoint" + # - "bash" + # - "-c" + # - "redis-cli set liveness-probe \"`date`\" | grep OK" + customLivenessProbe: {} + customReadinessProbe: {} + + ## Redis slave Resource + # resources: + # requests: + # memory: 256Mi + # cpu: 100m + + ## Redis slave selectors and tolerations for pod assignment + # nodeSelector: {"beta.kubernetes.io/arch": "amd64"} + # tolerations: [] + + ## Use an alternate scheduler, e.g. "stork". + ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ + ## + # schedulerName: + + ## Redis slave pod Annotation and Labels + podLabels: {} + podAnnotations: {} + + ## Redis slave pod priorityClassName + # priorityClassName: '' + + ## Enable persistence using Persistent Volume Claims + ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ + ## + persistence: + enabled: true + ## The path the volume will be mounted at, useful when using different + ## Redis images. + path: /data + ## The subdirectory of the volume to mount to, useful in dev environments + ## and one PV for multiple services. + subPath: "" + ## redis data Persistent Volume Storage Class + ## If defined, storageClassName: + ## If set to "-", storageClassName: "", which disables dynamic provisioning + ## If undefined (the default) or set to null, no storageClassName spec is + ## set, choosing the default provisioner. (gp2 on AWS, standard on + ## GKE, AWS & OpenStack) + ## + # storageClass: "-" + accessModes: + - ReadWriteOnce + size: 8Gi + ## Persistent Volume selectors + ## https://kubernetes.io/docs/concepts/storage/persistent-volumes/#selector + matchLabels: {} + matchExpressions: {} + + ## Update strategy, can be set to RollingUpdate or onDelete by default. + ## https://kubernetes.io/docs/tutorials/stateful-application/basic-stateful-set/#updating-statefulsets + statefulset: + labels: {} + annotations: {} + updateStrategy: RollingUpdate + ## Partition update strategy + ## https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#partitions + # rollingUpdatePartition: + + ## An array to add extra env vars + ## For example: + ## extraEnvVars: + ## - name: name + ## value: value + ## - name: other_name + ## valueFrom: + ## fieldRef: + ## fieldPath: fieldPath + ## + extraEnvVars: [] + + ## ConfigMap with extra env vars: + ## + extraEnvVarsCM: [] + + ## Secret with extra env vars: + ## + extraEnvVarsSecret: [] + +## Prometheus Exporter / Metrics +## +metrics: + enabled: true + + image: + registry: docker.io + repository: bitnami/redis-exporter + tag: 1.13.1-debian-10-r32 + pullPolicy: IfNotPresent + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## + # pullSecrets: + # - myRegistryKeySecretName + + ## Metrics exporter resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## + # resources: {} + + ## Extra arguments for Metrics exporter, for example: + ## extraArgs: + ## check-keys: myKey,myOtherKey + # extraArgs: {} + + ## Metrics exporter pod Annotation and Labels + podAnnotations: + prometheus.io/scrape: "true" + prometheus.io/port: "9121" + # podLabels: {} + + # Enable this if you're using https://github.com/coreos/prometheus-operator + serviceMonitor: + enabled: false + ## Specify a namespace if needed + # namespace: monitoring + # fallback to the prometheus default unless specified + # interval: 10s + ## Defaults to what's used if you follow CoreOS [Prometheus Install Instructions](https://github.com/bitnami/charts/tree/master/bitnami/prometheus-operator#tldr) + ## [Prometheus Selector Label](https://github.com/bitnami/charts/tree/master/bitnami/prometheus-operator#prometheus-operator-1) + ## [Kube Prometheus Selector Label](https://github.com/bitnami/charts/tree/master/bitnami/prometheus-operator#exporters) + selector: + prometheus: kube-prometheus + + ## Custom PrometheusRule to be defined + ## The value is evaluated as a template, so, for example, the value can depend on .Release or .Chart + ## ref: https://github.com/coreos/prometheus-operator#customresourcedefinitions + prometheusRule: + enabled: false + additionalLabels: {} + namespace: "" + ## Redis prometheus rules + ## These are just examples rules, please adapt them to your needs. + ## Make sure to constraint the rules to the current redis service. + # rules: + # - alert: RedisDown + # expr: redis_up{service="{{ template "redis.fullname" . }}-metrics"} == 0 + # for: 2m + # labels: + # severity: error + # annotations: + # summary: Redis instance {{ "{{ $labels.instance }}" }} down + # description: Redis instance {{ "{{ $labels.instance }}" }} is down + # - alert: RedisMemoryHigh + # expr: > + # redis_memory_used_bytes{service="{{ template "redis.fullname" . }}-metrics"} * 100 + # / + # redis_memory_max_bytes{service="{{ template "redis.fullname" . }}-metrics"} + # > 90 + # for: 2m + # labels: + # severity: error + # annotations: + # summary: Redis instance {{ "{{ $labels.instance }}" }} is using too much memory + # description: | + # Redis instance {{ "{{ $labels.instance }}" }} is using {{ "{{ $value }}" }}% of its available memory. + # - alert: RedisKeyEviction + # expr: | + # increase(redis_evicted_keys_total{service="{{ template "redis.fullname" . }}-metrics"}[5m]) > 0 + # for: 1s + # labels: + # severity: error + # annotations: + # summary: Redis instance {{ "{{ $labels.instance }}" }} has evicted keys + # description: | + # Redis instance {{ "{{ $labels.instance }}" }} has evicted {{ "{{ $value }}" }} keys in the last 5 minutes. + rules: [] + + ## Metrics exporter pod priorityClassName + # priorityClassName: '' + service: + type: ClusterIP + ## Use serviceLoadBalancerIP to request a specific static IP, + ## otherwise leave blank + # loadBalancerIP: + annotations: {} + labels: {} + +## +## Init containers parameters: +## volumePermissions: Change the owner of the persist volume mountpoint to RunAsUser:fsGroup +## +volumePermissions: + enabled: false + image: + registry: docker.io + repository: bitnami/minideb + tag: buster + pullPolicy: Always + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## + # pullSecrets: + # - myRegistryKeySecretName + resources: {} + # resources: + # requests: + # memory: 128Mi + # cpu: 100m + + ## Init container Security Context + ## Note: the chown of the data folder is done to containerSecurityContext.runAsUser + ## and not the below volumePermissions.securityContext.runAsUser + ## When runAsUser is set to special value "auto", init container will try to chwon the + ## data folder to autodetermined user&group, using commands: `id -u`:`id -G | cut -d" " -f2` + ## "auto" is especially useful for OpenShift which has scc with dynamic userids (and 0 is not allowed). + ## You may want to use this volumePermissions.securityContext.runAsUser="auto" in combination with + ## podSecurityContext.enabled=false,containerSecurityContext.enabled=false + ## + securityContext: + runAsUser: 0 + +## Redis config file +## ref: https://redis.io/topics/config +## +configmap: |- + # Enable AOF https://redis.io/topics/persistence#append-only-file + appendonly yes + # Disable RDB persistence, AOF persistence already enabled. + save "" +## Sysctl InitContainer +## used to perform sysctl operation to modify Kernel settings (needed sometimes to avoid warnings) +sysctlImage: + enabled: false + command: [] + registry: docker.io + repository: bitnami/minideb + tag: buster + pullPolicy: Always + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## + # pullSecrets: + # - myRegistryKeySecretName + mountHostSys: false + resources: {} + # resources: + # requests: + # memory: 128Mi + # cpu: 100m + +## PodSecurityPolicy configuration +## ref: https://kubernetes.io/docs/concepts/policy/pod-security-policy/ +## +podSecurityPolicy: + ## Specifies whether a PodSecurityPolicy should be created + ## + create: false + +## Define a disruption budget +## ref: https://kubernetes.io/docs/concepts/workloads/pods/disruptions/ +## +podDisruptionBudget: + enabled: false + minAvailable: 1 + # maxUnavailable: 1 diff --git a/x86_64-linux.zip b/x86_64-linux.zip deleted file mode 100644 index deb2468..0000000 Binary files a/x86_64-linux.zip and /dev/null differ