Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -66,3 +66,14 @@ nodeSelector:
true
{{- end }}
{{- end }}

{{- define "vpa.policyUpdateMode" -}}
{{- $kubeVersion := .Values.global.discovery.kubernetesVersion -}}
{{- $updateMode := "" -}}
{{- if semverCompare ">=1.33.0" $kubeVersion -}}
{{- $updateMode = "InPlaceOrRecreate" -}}
{{- else -}}
{{- $updateMode = "Recreate" -}}
{{- end }}
{{- $updateMode }}
{{- end }}
2 changes: 1 addition & 1 deletion templates/cdi/cdi-apiserver/vpa.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ spec:
kind: Deployment
name: cdi-apiserver
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_api_rewriter.vpa_container_policy" . | nindent 4 }}
Expand Down
2 changes: 1 addition & 1 deletion templates/cdi/cdi-deployment/vpa.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ spec:
kind: Deployment
name: cdi-deployment
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_api_rewriter.vpa_container_policy" . | nindent 4 }}
Expand Down
4 changes: 2 additions & 2 deletions templates/cdi/cdi-operator/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ spec:
kind: Deployment
name: cdi-operator
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_api_rewriter.vpa_container_policy" . | nindent 4 }}
Expand Down Expand Up @@ -89,7 +89,7 @@ spec:
) }}
{{- include "kube_rbac_proxy.sidecar_container" (tuple . $kubeRbacProxySettings) | nindent 6 }}
- name: cdi-operator
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all" . | nindent 8 }}
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all_pss_restricted" . | nindent 8 }}
env:
{{- include "kube_api_rewriter.kubeconfig_env" . | nindent 8 }}
{{- include "cdi_images" . | nindent 8 }}
Expand Down
4 changes: 2 additions & 2 deletions templates/dvcr/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ spec:
kind: Deployment
name: dvcr
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_rbac_proxy.vpa_container_policy" . | nindent 4 }}
Expand Down Expand Up @@ -66,7 +66,7 @@ spec:
{{ include "helm_lib_pod_anti_affinity_for_ha" (list . (dict "app" "dvcr")) | nindent 6 }}
containers:
- name: dvcr
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem" . | nindent 10 }}
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all_pss_restricted" . | nindent 10 }}
image: {{ include "helm_lib_module_image" (list . "dvcr") }}
imagePullPolicy: IfNotPresent
command:
Expand Down
2 changes: 1 addition & 1 deletion templates/kube-rbac-proxy/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
{{- $ctx := index . 0 }}
{{- $settings := index . 1 }}
- name: {{ $settings.containerName | default "kube-rbac-proxy" }}
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem" $ctx | nindent 2 }}
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all_pss_restricted" $ctx | nindent 2 }}
{{- if eq $settings.runAsUserNobody true }}
runAsNonRoot: true
runAsUser: 65534
Expand Down
2 changes: 1 addition & 1 deletion templates/kubevirt/virt-api/vpa.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ spec:
kind: Deployment
name: virt-api
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_api_rewriter.vpa_container_policy" . | nindent 4 }}
Expand Down
2 changes: 1 addition & 1 deletion templates/kubevirt/virt-controller/vpa.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ spec:
kind: Deployment
name: virt-controller
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_api_rewriter.vpa_container_policy" . | nindent 4 }}
Expand Down
2 changes: 1 addition & 1 deletion templates/kubevirt/virt-handler/vpa.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ spec:
kind: DaemonSet
name: virt-handler
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_api_rewriter.vpa_container_policy" . | nindent 4 }}
Expand Down
4 changes: 2 additions & 2 deletions templates/kubevirt/virt-operator/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ spec:
kind: Deployment
name: virt-operator
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_api_rewriter.vpa_container_policy" . | nindent 4 }}
Expand Down Expand Up @@ -107,7 +107,7 @@ spec:
) }}
{{- include "kube_rbac_proxy.sidecar_container" (tuple . $kubeRbacProxySettings) | nindent 6 }}
- name: virt-operator
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all" . | nindent 8 }}
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all_pss_restricted" . | nindent 8 }}
args:
- --port
- "8443"
Expand Down
4 changes: 2 additions & 2 deletions templates/pre-delete-hook/job.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,8 @@ spec:
restartPolicy: Never
serviceAccountName: virtualization-pre-delete-hook
containers:
- name: virtualization-pre-delete-hook
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem" . | nindent 8 }}
- name: pre-delete-hook
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all_pss_restricted" . | nindent 8 }}
image: {{ include "helm_lib_module_image" (list . "preDeleteHook") }}
env:
- name: WAIT_TIMEOUT
Expand Down
4 changes: 2 additions & 2 deletions templates/virtualization-api/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ spec:
kind: Deployment
name: virtualization-api
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
- containerName: virtualization-api
Expand Down Expand Up @@ -75,7 +75,7 @@ spec:
{{ include "helm_lib_pod_anti_affinity_for_ha" (list . (dict "app" "virtualization-api")) | nindent 6 }}
containers:
- name: virtualization-api
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem" . | nindent 10 }}
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all_pss_restricted" . | nindent 10 }}
args:
- --kubevirt-cabundle=/etc/virt-api/certificates/ca.crt
- --kubevirt-endpoint=virt-api.d8-{{ .Chart.Name}}.svc
Expand Down
2 changes: 1 addition & 1 deletion templates/virtualization-audit/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ spec:
kind: Deployment
name: virtualization-audit
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
- containerName: virtualization-audit
Expand Down
4 changes: 2 additions & 2 deletions templates/virtualization-controller/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ spec:
kind: Deployment
name: virtualization-controller
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
{{- include "kube_api_rewriter.vpa_container_policy" . | nindent 4 }}
Expand Down Expand Up @@ -78,7 +78,7 @@ spec:
containers:
{{- include "kube_api_rewriter.sidecar_container" . | nindent 8 }}
- name: virtualization-controller
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem" . | nindent 10 }}
{{- include "helm_lib_module_container_security_context_read_only_root_filesystem_capabilities_drop_all_pss_restricted" . | nindent 10 }}
image: {{ include "helm_lib_module_image" (list . "virtualizationController") }}
imagePullPolicy: IfNotPresent
{{- if (.Values.global.enabledModules | has "sdn") }}
Expand Down
2 changes: 1 addition & 1 deletion templates/vm-route-forge/daemonset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ spec:
kind: DaemonSet
name: vm-route-forge
updatePolicy:
updateMode: "Auto"
updateMode: {{ include "vpa.policyUpdateMode" . }}
resourcePolicy:
containerPolicies:
- containerName: vm-route-forge
Expand Down
Loading