update to flux 0.7.2

This commit is contained in:
2021-01-27 02:05:14 +00:00
parent e901c202d4
commit 1498461bfa
@@ -79,6 +79,8 @@ spec:
- HelmChart - HelmChart
- HelmRepository - HelmRepository
- ImageRepository - ImageRepository
- ImagePolicy
- ImageUpdateAutomation
type: string type: string
name: name:
description: Name of the referent description: Name of the referent
@@ -98,8 +100,10 @@ spec:
description: Send events using this provider description: Send events using this provider
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
summary: summary:
description: Short description of the impact and affected cluster. description: Short description of the impact and affected cluster.
@@ -247,8 +251,10 @@ spec:
description: The name of the secret containing authentication credentials for the Bucket. description: The name of the secret containing authentication credentials for the Bucket.
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
suspend: suspend:
description: This flag tells the controller to suspend the reconciliation of this source. description: This flag tells the controller to suspend the reconciliation of this source.
@@ -437,8 +443,10 @@ spec:
description: The secret name containing the Git credentials. For HTTPS repositories the secret must contain username and password fields. For SSH repositories the secret must contain identity, identity.pub and known_hosts fields. description: The secret name containing the Git credentials. For HTTPS repositories the secret must contain username and password fields. For SSH repositories the secret must contain identity, identity.pub and known_hosts fields.
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
suspend: suspend:
description: This flag tells the controller to suspend the reconciliation of this source. description: This flag tells the controller to suspend the reconciliation of this source.
@@ -463,8 +471,10 @@ spec:
description: The secret name containing the public keys of all trusted Git authors. description: The secret name containing the public keys of all trusted Git authors.
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
required: required:
- mode - mode
@@ -919,8 +929,10 @@ spec:
description: SecretRef holds the name to a secret that contains a 'value' key with the kubeconfig file as the value. It must be in the same namespace as the HelmRelease. It is recommended that the kubeconfig is self-contained, and the secret is regularly updated if credentials such as a cloud-access-token expire. Cloud specific `cmd-path` auth helpers will not function without adding binaries and credentials to the Pod that is responsible for reconciling the HelmRelease. description: SecretRef holds the name to a secret that contains a 'value' key with the kubeconfig file as the value. It must be in the same namespace as the HelmRelease. It is recommended that the kubeconfig is self-contained, and the secret is regularly updated if credentials such as a cloud-access-token expire. Cloud specific `cmd-path` auth helpers will not function without adding binaries and credentials to the Pod that is responsible for reconciling the HelmRelease.
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
type: object type: object
maxHistory: maxHistory:
@@ -956,6 +968,11 @@ spec:
serviceAccountName: serviceAccountName:
description: The name of the Kubernetes service account to impersonate when reconciling this HelmRelease. description: The name of the Kubernetes service account to impersonate when reconciling this HelmRelease.
type: string type: string
storageNamespace:
description: StorageNamespace used for the Helm storage. Defaults to the namespace of the HelmRelease.
maxLength: 63
minLength: 1
type: string
suspend: suspend:
description: Suspend tells the controller to suspend reconciliation for this HelmRelease, it does not apply to already started reconciliations. Defaults to false. description: Suspend tells the controller to suspend reconciliation for this HelmRelease, it does not apply to already started reconciliations. Defaults to false.
type: boolean type: boolean
@@ -1223,8 +1240,10 @@ spec:
description: The name of the secret containing authentication credentials for the Helm repository. For HTTP/S basic auth the secret must contain username and password fields. For TLS the secret must contain a certFile and keyFile, and/or caCert fields. description: The name of the secret containing authentication credentials for the Helm repository. For HTTP/S basic auth the secret must contain username and password fields. For TLS the secret must contain a certFile and keyFile, and/or caCert fields.
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
suspend: suspend:
description: This flag tells the controller to suspend the reconciliation of this source. description: This flag tells the controller to suspend the reconciliation of this source.
@@ -1392,8 +1411,10 @@ spec:
description: The secret name containing the private OpenPGP keys used for decryption. description: The secret name containing the private OpenPGP keys used for decryption.
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
required: required:
- provider - provider
@@ -1416,10 +1437,10 @@ spec:
healthChecks: healthChecks:
description: A list of resources to be included in the health assessment. description: A list of resources to be included in the health assessment.
items: items:
description: CrossNamespaceObjectReference contains enough information to let you locate the typed referenced object at cluster level description: NamespacedObjectKindReference contains enough information to let you locate the typed referenced object in any namespace
properties: properties:
apiVersion: apiVersion:
description: API version of the referent, defaults to 'apps/v1' description: API version of the referent, if not specified the Kubernetes preferred version will be used
type: string type: string
kind: kind:
description: Kind of the referent description: Kind of the referent
@@ -1428,7 +1449,7 @@ spec:
description: Name of the referent description: Name of the referent
type: string type: string
namespace: namespace:
description: Namespace of the referent description: Namespace of the referent, when not specified it acts as LocalObjectReference
type: string type: string
required: required:
- kind - kind
@@ -1465,8 +1486,10 @@ spec:
description: SecretRef holds the name to a secret that contains a 'value' key with the kubeconfig file as the value. It must be in the same namespace as the Kustomization. It is recommended that the kubeconfig is self-contained, and the secret is regularly updated if credentials such as a cloud-access-token expire. Cloud specific `cmd-path` auth helpers will not function without adding binaries and credentials to the Pod that is responsible for reconciling the Kustomization. description: SecretRef holds the name to a secret that contains a 'value' key with the kubeconfig file as the value. It must be in the same namespace as the Kustomization. It is recommended that the kubeconfig is self-contained, and the secret is regularly updated if credentials such as a cloud-access-token expire. Cloud specific `cmd-path` auth helpers will not function without adding binaries and credentials to the Pod that is responsible for reconciling the Kustomization.
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
type: object type: object
path: path:
@@ -1475,6 +1498,9 @@ spec:
prune: prune:
description: Prune enables garbage collection. description: Prune enables garbage collection.
type: boolean type: boolean
retryInterval:
description: The interval at which to retry a previously failed reconciliation. When not specified, the controller uses the KustomizationSpec.Interval value to retry failures.
type: string
serviceAccountName: serviceAccountName:
description: The name of the Kubernetes service account to impersonate when reconciling this Kustomization. description: The name of the Kubernetes service account to impersonate when reconciling this Kustomization.
type: string type: string
@@ -1682,8 +1708,10 @@ spec:
description: Secret reference containing the provider webhook URL using "address" as data key description: Secret reference containing the provider webhook URL using "address" as data key
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
type: type:
description: Type of provider description: Type of provider
@@ -1831,6 +1859,8 @@ spec:
- HelmChart - HelmChart
- HelmRepository - HelmRepository
- ImageRepository - ImageRepository
- ImagePolicy
- ImageUpdateAutomation
type: string type: string
name: name:
description: Name of the referent description: Name of the referent
@@ -1850,8 +1880,10 @@ spec:
description: Secret reference containing the token used to validate the payload authenticity description: Secret reference containing the token used to validate the payload authenticity
properties: properties:
name: name:
description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid?' description: Name of the referent
type: string type: string
required:
- name
type: object type: object
suspend: suspend:
description: This flag tells the controller to suspend subsequent events handling. Defaults to false. description: This flag tells the controller to suspend subsequent events handling. Defaults to false.
@@ -1860,6 +1892,7 @@ spec:
description: Type of webhook sender, used to determine the validation procedure and payload deserialization. description: Type of webhook sender, used to determine the validation procedure and payload deserialization.
enum: enum:
- generic - generic
- generic-hmac
- github - github
- gitlab - gitlab
- bitbucket - bitbucket
@@ -1867,6 +1900,7 @@ spec:
- dockerhub - dockerhub
- quay - quay
- gcr - gcr
- nexus
type: string type: string
required: required:
- resources - resources
@@ -1934,14 +1968,49 @@ status:
conditions: [] conditions: []
storedVersions: [] storedVersions: []
--- ---
apiVersion: v1
kind: ServiceAccount
metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/version: latest
name: helm-controller
namespace: flux-system
---
apiVersion: v1
kind: ServiceAccount
metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/version: latest
name: kustomize-controller
namespace: flux-system
---
apiVersion: v1
kind: ServiceAccount
metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/version: latest
name: notification-controller
namespace: flux-system
---
apiVersion: v1
kind: ServiceAccount
metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/version: latest
name: source-controller
namespace: flux-system
---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: Role kind: ClusterRole
metadata: metadata:
labels: labels:
app.kubernetes.io/instance: flux-system app.kubernetes.io/instance: flux-system
app.kubernetes.io/version: latest app.kubernetes.io/version: latest
name: crd-controller-flux-system name: crd-controller-flux-system
namespace: flux-system
rules: rules:
- apiGroups: - apiGroups:
- source.toolkit.fluxcd.io - source.toolkit.fluxcd.io
@@ -1968,12 +2037,19 @@ rules:
verbs: verbs:
- '*' - '*'
- apiGroups: - apiGroups:
- "" - image.toolkit.fluxcd.io
resources: resources:
- configmaps - '*'
- configmaps/status
verbs: verbs:
- '*' - '*'
- apiGroups:
- ""
resources:
- secrets
verbs:
- get
- list
- watch
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
@@ -1981,23 +2057,31 @@ rules:
verbs: verbs:
- create - create
- patch - patch
--- - apiGroups:
apiVersion: rbac.authorization.k8s.io/v1 - ""
kind: RoleBinding resources:
metadata: - configmaps
labels: - configmaps/status
app.kubernetes.io/instance: flux-system verbs:
app.kubernetes.io/version: latest - get
name: crd-controller-flux-system - list
namespace: flux-system - watch
roleRef: - create
apiGroup: rbac.authorization.k8s.io - update
kind: Role - patch
name: crd-controller-flux-system - delete
subjects: - apiGroups:
- kind: ServiceAccount - coordination.k8s.io
name: default resources:
namespace: flux-system - leases
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -2012,7 +2096,41 @@ roleRef:
name: cluster-admin name: cluster-admin
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: default name: kustomize-controller
namespace: flux-system
- kind: ServiceAccount
name: helm-controller
namespace: flux-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/version: latest
name: crd-controller-flux-system
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: crd-controller-flux-system
subjects:
- kind: ServiceAccount
name: kustomize-controller
namespace: flux-system
- kind: ServiceAccount
name: helm-controller
namespace: flux-system
- kind: ServiceAccount
name: source-controller
namespace: flux-system
- kind: ServiceAccount
name: notification-controller
namespace: flux-system
- kind: ServiceAccount
name: image-reflector-controller
namespace: flux-system
- kind: ServiceAccount
name: image-automation-controller
namespace: flux-system namespace: flux-system
--- ---
apiVersion: v1 apiVersion: v1
@@ -2106,7 +2224,7 @@ spec:
valueFrom: valueFrom:
fieldRef: fieldRef:
fieldPath: metadata.namespace fieldPath: metadata.namespace
image: ghcr.io/fluxcd/helm-controller:v0.5.2 image: ghcr.io/fluxcd/helm-controller:v0.6.1
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
livenessProbe: livenessProbe:
httpGet: httpGet:
@@ -2138,6 +2256,7 @@ spec:
name: temp name: temp
nodeSelector: nodeSelector:
kubernetes.io/os: linux kubernetes.io/os: linux
serviceAccountName: helm-controller
terminationGracePeriodSeconds: 600 terminationGracePeriodSeconds: 600
volumes: volumes:
- emptyDir: {} - emptyDir: {}
@@ -2177,7 +2296,7 @@ spec:
valueFrom: valueFrom:
fieldRef: fieldRef:
fieldPath: metadata.namespace fieldPath: metadata.namespace
image: ghcr.io/fluxcd/kustomize-controller:v0.6.3 image: ghcr.io/fluxcd/kustomize-controller:v0.7.2
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
livenessProbe: livenessProbe:
httpGet: httpGet:
@@ -2211,6 +2330,7 @@ spec:
kubernetes.io/os: linux kubernetes.io/os: linux
securityContext: securityContext:
fsGroup: 1337 fsGroup: 1337
serviceAccountName: kustomize-controller
terminationGracePeriodSeconds: 60 terminationGracePeriodSeconds: 60
volumes: volumes:
- emptyDir: {} - emptyDir: {}
@@ -2249,7 +2369,7 @@ spec:
valueFrom: valueFrom:
fieldRef: fieldRef:
fieldPath: metadata.namespace fieldPath: metadata.namespace
image: ghcr.io/fluxcd/notification-controller:v0.6.2 image: ghcr.io/fluxcd/notification-controller:v0.7.1
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
livenessProbe: livenessProbe:
httpGet: httpGet:
@@ -2285,6 +2405,7 @@ spec:
name: temp name: temp
nodeSelector: nodeSelector:
kubernetes.io/os: linux kubernetes.io/os: linux
serviceAccountName: notification-controller
terminationGracePeriodSeconds: 10 terminationGracePeriodSeconds: 10
volumes: volumes:
- emptyDir: {} - emptyDir: {}
@@ -2326,7 +2447,7 @@ spec:
valueFrom: valueFrom:
fieldRef: fieldRef:
fieldPath: metadata.namespace fieldPath: metadata.namespace
image: ghcr.io/fluxcd/source-controller:v0.6.3 image: ghcr.io/fluxcd/source-controller:v0.7.1
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
livenessProbe: livenessProbe:
httpGet: httpGet:
@@ -2359,6 +2480,7 @@ spec:
name: tmp name: tmp
nodeSelector: nodeSelector:
kubernetes.io/os: linux kubernetes.io/os: linux
serviceAccountName: source-controller
terminationGracePeriodSeconds: 10 terminationGracePeriodSeconds: 10
volumes: volumes:
- emptyDir: {} - emptyDir: {}