(dev-v2.6-archive) bump rancher-webhook to 0.2.1-rc1

(partially cherry picked from commit cc5908e4cc)
pull/1680/head
Jiaqi Luo 2021-09-15 16:38:18 -07:00 committed by Arvind Iyengar
parent 36fe5d9992
commit 3f73dd78a1
No known key found for this signature in database
GPG Key ID: A8DD9BFD6C811498
16 changed files with 59 additions and 46 deletions

View File

@ -1,2 +1,2 @@
url: https://github.com/rancher/aks-operator/releases/download/v1.0.1/rancher-aks-operator-crd-1.0.1.tgz url: https://github.com/rancher/aks-operator/releases/download/v1.0.2-rc1/rancher-aks-operator-crd-1.0.2-rc1.tgz
version: 100.0.0 version: 100.0.1

View File

@ -1,2 +1,2 @@
url: https://github.com/rancher/aks-operator/releases/download/v1.0.1/rancher-aks-operator-1.0.1.tgz url: https://github.com/rancher/aks-operator/releases/download/v1.0.2-rc1/rancher-aks-operator-1.0.2-rc1.tgz
version: 100.0.0 version: 100.0.1

View File

@ -1,5 +1,5 @@
apiVersion: v1 apiVersion: v1
appVersion: v1.0.5 appVersion: v1.0.6
description: The cis-operator enables running CIS benchmark security scans on a kubernetes cluster description: The cis-operator enables running CIS benchmark security scans on a kubernetes cluster
name: rancher-cis-benchmark name: rancher-cis-benchmark
version: 1.0.6 version: 1.0.6
@ -16,3 +16,4 @@ annotations:
catalog.cattle.io/display-name: "CIS Benchmark" catalog.cattle.io/display-name: "CIS Benchmark"
catalog.cattle.io/os: linux catalog.cattle.io/os: linux
catalog.cattle.io/auto-install: rancher-cis-benchmark-crd=match catalog.cattle.io/auto-install: rancher-cis-benchmark-crd=match
catalog.cattle.io/rancher-version: ">= 2.6.0"

View File

@ -5,13 +5,13 @@
image: image:
cisoperator: cisoperator:
repository: rancher/cis-operator repository: rancher/cis-operator
tag: v1.0.5 tag: v1.0.6-rc1
securityScan: securityScan:
repository: rancher/security-scan repository: rancher/security-scan
tag: v0.2.3 tag: v0.2.4-rc1
sonobuoy: sonobuoy:
repository: rancher/mirrored-sonobuoy-sonobuoy repository: rancher/mirrored-sonobuoy-sonobuoy
tag: v0.16.3 tag: v0.53.2
resources: {} resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious # We usually recommend not to specify default resources and to leave this as a conscious

View File

@ -1,5 +1,5 @@
url: local url: local
version: 2.0.0 version: 2.0.1
additionalCharts: additionalCharts:
- workingDir: charts-crd - workingDir: charts-crd
crdOptions: crdOptions:

View File

@ -2,18 +2,20 @@
+++ charts/Chart.yaml +++ charts/Chart.yaml
@@ -1,10 +1,22 @@ @@ -1,10 +1,22 @@
apiVersion: v2 apiVersion: v2
appVersion: v3.5.1 appVersion: v3.6.0
-description: A Helm chart for Gatekeeper -description: A Helm chart for Gatekeeper
+description: Modifies Open Policy Agent's upstream gatekeeper chart that provides policy-based control for cloud native environments +description: Modifies Open Policy Agent's upstream gatekeeper chart that provides policy-based control for cloud native environments
home: https://github.com/open-policy-agent/gatekeeper home: https://github.com/open-policy-agent/gatekeeper
keywords: keywords:
- open policy agent -- open policy agent
-name: gatekeeper -name: gatekeeper
+- security + - open policy agent
+ - security
+name: rancher-gatekeeper +name: rancher-gatekeeper
sources: sources:
- https://github.com/open-policy-agent/gatekeeper.git -- https://github.com/open-policy-agent/gatekeeper.git
version: 3.5.1 + - https://github.com/open-policy-agent/gatekeeper.git
version: 3.6.0
+icon: https://charts.rancher.io/assets/logos/gatekeeper.svg +icon: https://charts.rancher.io/assets/logos/gatekeeper.svg
+annotations: +annotations:
+ catalog.cattle.io/certified: rancher + catalog.cattle.io/certified: rancher

View File

@ -1,6 +1,6 @@
--- charts-original/templates/gatekeeper-audit-deployment.yaml --- charts-original/templates/gatekeeper-audit-deployment.yaml
+++ charts/templates/gatekeeper-audit-deployment.yaml +++ charts/templates/gatekeeper-audit-deployment.yaml
@@ -63,7 +63,7 @@ @@ -65,7 +65,7 @@
valueFrom: valueFrom:
fieldRef: fieldRef:
fieldPath: metadata.name fieldPath: metadata.name

View File

@ -1,6 +1,6 @@
--- charts-original/templates/gatekeeper-controller-manager-deployment.yaml --- charts-original/templates/gatekeeper-controller-manager-deployment.yaml
+++ charts/templates/gatekeeper-controller-manager-deployment.yaml +++ charts/templates/gatekeeper-controller-manager-deployment.yaml
@@ -65,7 +65,7 @@ @@ -71,7 +71,7 @@
valueFrom: valueFrom:
fieldRef: fieldRef:
fieldPath: metadata.name fieldPath: metadata.name

View File

@ -0,0 +1,11 @@
--- charts-original/templates/upgrade-crds-hook.yaml
+++ charts/templates/upgrade-crds-hook.yaml
@@ -72,7 +72,7 @@
restartPolicy: Never
containers:
- name: crds-upgrade
- image: '{{ .Values.image.crdRepository }}:{{ .Values.image.release }}'
+ image: '{{ template "system_default_registry" . }}{{ .Values.image.crdRepository }}:{{ .Values.image.tag }}'
imagePullPolicy: '{{ .Values.image.pullPolicy }}'
args:
- apply

View File

@ -7,7 +7,7 @@
auditMatchKindOnly: false auditMatchKindOnly: false
constraintViolationsLimit: 20 constraintViolationsLimit: 20
auditFromCache: false auditFromCache: false
@@ -16,13 +16,13 @@ @@ -19,14 +19,14 @@
labelNamespace: labelNamespace:
enabled: true enabled: true
image: image:
@ -19,13 +19,15 @@
pullSecrets: [] pullSecrets: []
image: image:
- repository: openpolicyagent/gatekeeper - repository: openpolicyagent/gatekeeper
- release: v3.5.1 - crdRepository: openpolicyagent/gatekeeper-crds
- release: v3.6.0
+ repository: rancher/mirrored-openpolicyagent-gatekeeper + repository: rancher/mirrored-openpolicyagent-gatekeeper
+ tag: v3.5.1 + crdRepository: rancher/mirrored-openpolicyagent-gatekeeper-crds
+ tag: v3.6.0
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
pullSecrets: [] pullSecrets: []
podAnnotations: podAnnotations:
@@ -70,5 +70,11 @@ @@ -80,5 +80,11 @@
pdb: pdb:
controllerManager: controllerManager:
minAvailable: 1 minAvailable: 1

View File

@ -1,5 +1,5 @@
url: https://open-policy-agent.github.io/gatekeeper/charts/gatekeeper-3.5.1.tgz url: https://open-policy-agent.github.io/gatekeeper/charts/gatekeeper-3.6.0.tgz
version: 100.0.0 version: 100.0.1
additionalCharts: additionalCharts:
- workingDir: charts-crd - workingDir: charts-crd
crdOptions: crdOptions:

View File

@ -1,5 +1,5 @@
apiVersion: v1 apiVersion: v1
version: 3.5.1 version: 3.6.0
description: Installs the CRDs for rancher-gatekeeper. description: Installs the CRDs for rancher-gatekeeper.
name: rancher-gatekeeper-crd name: rancher-gatekeeper-crd
type: application type: application

View File

@ -39,17 +39,25 @@ spec:
- "true" - "true"
{{- end }} {{- end }}
serviceAccountName: vsphere-csi-controller serviceAccountName: vsphere-csi-controller
{{- if .Values.csiController.tolerations }}
tolerations: tolerations:
{{- with .Values.csiController.tolerations }} # Rancher specific change: These tolerations are intentionally different from upstream to avoid lessening the scope to only NoSchedule with a specific key
{{- toYaml . | nindent 8 }} # - key: node-role.kubernetes.io/master
{{- end }} # operator: Exists
{{- else }} # effect: NoSchedule
tolerations: - operator: "Exists"
- key: node-role.kubernetes.io/master
operator: Exists
effect: NoSchedule effect: NoSchedule
{{- end }} - operator: "Exists"
effect: NoExecute
# uncomment below toleration if you need an aggressive pod eviction in case when
# node becomes not-ready or unreachable. Default is 300 seconds if not specified.
#- key: node.kubernetes.io/not-ready
# operator: Exists
# effect: NoExecute
# tolerationSeconds: 30
#- key: node.kubernetes.io/unreachable
# operator: Exists
# effect: NoExecute
# tolerationSeconds: 30
dnsPolicy: "Default" dnsPolicy: "Default"
containers: containers:
- name: csi-attacher - name: csi-attacher

View File

@ -42,17 +42,6 @@ csiController:
repository: rancher/mirrored-k8scsi-csi-provisioner repository: rancher/mirrored-k8scsi-csi-provisioner
tag: v2.1.0 tag: v2.1.0
nodeSelector: {} nodeSelector: {}
# Uncomment below toleration if you need an aggressive pod eviction in case when
# node becomes not-ready or unreachable. Default is 300 seconds if not specified.
# tolerations:
# - key: node.kubernetes.io/not-ready
# operator: Exists
# effect: NoExecute
# tolerationSeconds: 30
# - key: node.kubernetes.io/unreachable
# operator: Exists
# effect: NoExecute
# tolerationSeconds: 30
# Internal features # Internal features
csiMigration: csiMigration:

View File

@ -1,2 +1,2 @@
url: local url: local
version: 100.0.1 version: 100.0.0

View File

@ -1,2 +1,2 @@
url: https://github.com/rancher/webhook/releases/download/v0.2.0/rancher-webhook-0.2.0.tgz url: https://github.com/rancher/webhook/releases/download/v0.2.1-rc1/rancher-webhook-0.2.1-rc1.tgz
version: 1.0.0 version: 1.0.1