Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions class/csi-driver-nfs.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,28 @@
parameters:
kapitan:
dependencies:
- type: helm
source: ${csi_driver_nfs:charts:csi-driver-nfs:source}
chart_name: csi-driver-nfs
version: ${csi_driver_nfs:charts:csi-driver-nfs:version}
output_path: ${_base_directory}/helmcharts/csi-driver-nfs/v${csi_driver_nfs:charts:csi-driver-nfs:version}

compile:
- input_paths:
- ${_base_directory}/component/app.jsonnet
input_type: jsonnet
output_path: .
- output_path: ${_instance}/10_helmchart
input_type: helm
output_type: yaml
input_paths:
- ${_base_directory}/helmcharts/csi-driver-nfs/v${csi_driver_nfs:charts:csi-driver-nfs:version}
helm_values: ${csi_driver_nfs:helmValues}
helm_params:
name: csi-driver-nfs
namespace: '${csi_driver_nfs:namespace}'
- input_paths:
- ${_base_directory}/component/main.jsonnet
- ${_base_directory}/component/storageclasses.jsonnet
input_type: jsonnet
output_path: csi-driver-nfs/
29 changes: 29 additions & 0 deletions class/defaults.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,3 +3,32 @@ parameters:
=_metadata:
multi_tenant: true
namespace: syn-csi-driver-nfs

charts:
csi-driver-nfs:
source: https://raw.githubusercontent.com/kubernetes-csi/csi-driver-nfs/master/charts
version: 4.13.2

images:
nfs:
registry: registry.k8s.io
repository: sig-storage/nfsplugin
tag: v4.13.2

storageClassDefaults: {}
storageClasses: {}

controller:
serviceAccountName: csi-nfs-controller-sa

node:
serviceAccountName: csi-nfs-node-sa

helmValues:
serviceAccount:
controller: ${csi_driver_nfs:controller:serviceAccountName}
node: ${csi_driver_nfs:node:serviceAccountName}
image:
nfs:
repository: ${csi_driver_nfs:images:nfs:registry}/${csi_driver_nfs:images:nfs:repository}
tag: ${csi_driver_nfs:images:nfs:tag}
35 changes: 33 additions & 2 deletions component/main.jsonnet
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,40 @@
local kap = import 'lib/kapitan.libjsonnet';
local kube = import 'lib/kube.libjsonnet';
local inv = kap.inventory();
// The hiera parameters for the component
local params = inv.parameters.csi_driver_nfs;

// Define outputs below
local isOpenshift = std.member([ 'openshift4', 'oke' ], inv.parameters.facts.distribution);

local sccRBAC = [
kube.RoleBinding('scc-privileged') {
roleRef: {
apiGroup: 'rbac.authorization.k8s.io',
kind: 'ClusterRole',
name: 'system:openshift:scc:privileged',
},
subjects: [
{
kind: 'ServiceAccount',
name: params.controller.serviceAccountName,
},
{
kind: 'ServiceAccount',
name: params.node.serviceAccountName,
},
],
},
];

{
'00_namespace': kube.Namespace(params.namespace) {
metadata+: {
annotations: {
'openshift.io/node-selector': '',
},
labels: {
'openshift.io/cluster-monitoring': 'true',
},
},
},
[if isOpenshift then '02_scc_rbac']: sccRBAC,
}
39 changes: 39 additions & 0 deletions component/storageclasses.jsonnet
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
local com = import 'lib/commodore.libjsonnet';
local kap = import 'lib/kapitan.libjsonnet';
local kube = import 'lib/kube.libjsonnet';
local sc = import 'lib/storageclass.libsonnet';

local inv = kap.inventory();
local params = inv.parameters.csi_driver_nfs;

local scDefaults = params.storageClassDefaults;
// get provisioner name from Helm values, falling back on driver default of
// `nfs.csi.k8s.io`.
local provisionerName =
std.get(
params.helmValues, 'driver', { name: 'nfs.csi.k8s.io' }
).name;

local storageclasses = std.map(
function(sc)
if
!std.objectHas(sc, 'parameters') ||
!std.isObject(sc.parameters) ||
!std.objectHas(sc.parameters, 'server') ||
!std.objectHas(sc.parameters, 'share')
then
error 'StorageClass "%s" for NFS CSI driver is invalid: one or more of `parameters.server` and `parameters.share` are missing!' % [ sc.metadata.name ]
else
sc {
provisioner: provisionerName,
},
com.generateResources(
params.storageClasses,
function(name) sc.storageClass(name) + com.makeMergeable(scDefaults)
)
);


{
[if std.length(storageclasses) > 0 then '50_storageclasses']: storageclasses,
}
82 changes: 82 additions & 0 deletions docs/modules/ROOT/pages/references/parameters.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,88 @@ default:: `syn-csi-driver-nfs`

The namespace in which to deploy this component.

== `charts`

[horizontal]
type:: object
default:: https://github.com/projectsyn/component-csi-driver-nfs/blob/master/class/defaults.yml[See `class/defaults.yml`]

The Helm chart for the NFS CSI driver.

== `images`

[horizontal]
type:: object
default:: https://github.com/projectsyn/component-csi-driver-nfs/blob/master/class/defaults.yml[See `class/defaults.yml`]

The container image used by the NFS CSI driver.

TIP: Helm value `image.baseRepo` allows overriding the container image registry for all images that aren't defined in this parameter.

== `storageClassDefaults`

[horizontal]
type:: object
default:: `{}`

Storage class configurations which are used as the base configuration for each storage class defined in parameter `storageClasses`.

== `storageClasses`

[horizontal]
type:: object
default:: `{}`

Each key-value pair defined in this parameter is used to render a `StorageClass` resource.
Entries with `null` values are dropped.
The key is used as `metadata.name` of the resulting `StorageClass` resource.
The value merged over the configuration defined in parameter `storageClassDefaults` to form the `StorageClass` resource.
Field `provisioner` of each `StorageClass` resource is set to `helmValues.driver.name`, falling back to `nfs.csi.k8s.io` if the Helm value isn't set.
Values for `provisioner` which are set in parameter `storageClassDefaults` or the value of an entry of this parameter are overwritten.

TIP: The component uses component [`storageclass`], so this component respects globally defined storage class default configurations and the globally defined default storage class.

NOTE: Apart from enforcing that each storage class sets `parameters.server` and `parameters.share`, the component doesn't validate whether the resulting `StorageClass` resources are valid.

== `controller`

[horizontal]
type:: object

Configurations for the NFS CSI controller.

=== `controller.serviceAccountName`

[horizontal]
type:: string
default:: `csi-nfs-controller-sa`

The service account name for the NFS CSI controller.
This parameter is passed to the Helm chart and used by the component to configure a `RoleBinding` to grant the controller access to the `privileged` SCC on OpenShift.

== `node`

[horizontal]
type:: object

Configurations for the NFS CSI node daemonset.

=== `node.serviceAccountName`

[horizontal]
type:: string
default:: `csi-nfs-node-sa`

The service account name for the NFS CSI node daemonset.
This parameter is passed to the Helm chart and used by the component to configure a `RoleBinding` to grant the node daemonset access to the `privileged` SCC on OpenShift.

== `helmValues`

[horizontal]
type:: object
default:: https://github.com/projectsyn/component-csi-driver-nfs/blob/master/class/defaults.yml[See `class/defaults.yml]

The Helm values that are used to render the Helm chart.

== Example

Expand Down
4 changes: 4 additions & 0 deletions renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,10 @@
"automerge",
"bump:patch"
]
},
{
"matchPackageNames": ["csi-driver-nfs", "registry.k8s.io/sig-storage/nfsplugin"],
"groupName": "dependency csi-driver-nfs"
}
]
}
29 changes: 27 additions & 2 deletions tests/defaults.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,28 @@
# Overwrite parameters here
parameters:
kapitan:
dependencies:
- type: https
source: https://raw.githubusercontent.com/projectsyn/component-storageclass/v1.0.0/lib/storageclass.libsonnet
output_path: vendor/lib/storageclass.libsonnet

# parameters: {...}
storageclass:
defaultClass: nfs
defaults: {}

csi_driver_nfs:
storageClassDefaults:
reclaimPolicy: Delete
volumeBindingMode: WaitForFirstConsumer
allowVolumeExpansion: true
mountOptions:
- nfsvers=4.1
storageClasses:
nfs1-example-com:
parameters:
server: nfs1.example.com
share: /
nfs2-example-net:
parameters:
server: nfs2.example.net
share: /exports/k8s
removed: null
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
apiVersion: v1
kind: Namespace
metadata:
annotations:
openshift.io/node-selector: ''
labels:
openshift.io/cluster-monitoring: 'true'
name: syn-csi-driver-nfs
Loading
Loading