Skip to content

Commit 9908884

Browse files
committed
helm create cyberark-disco-agent
Signed-off-by: Richard Wall <[email protected]>
1 parent 0c0ac0f commit 9908884

File tree

14 files changed

+692
-15
lines changed

14 files changed

+692
-15
lines changed

.envrc.template

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
# Variables required for hack/e2e/ca/test.sh
2+
export OCI_BASE=ttl.sh/f702739d-6123-4070-8b2d-b90707d44f8b/cyberark-disco-agent
3+
export ARK_USERNAME=
4+
export ARK_SECRET=
5+
export ARK_PLATFORM_DOMAIN=
6+
export ARK_SUBDOMAIN=
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
# Patterns to ignore when building packages.
2+
# This supports shell glob matching, relative path matching, and
3+
# negation (prefixed with !). Only one pattern per line.
4+
.DS_Store
5+
# Common VCS dirs
6+
.git/
7+
.gitignore
8+
.bzr/
9+
.bzrignore
10+
.hg/
11+
.hgignore
12+
.svn/
13+
# Common backup files
14+
*.swp
15+
*.bak
16+
*.tmp
17+
*.orig
18+
*~
19+
# Various IDEs
20+
.project
21+
.idea/
22+
*.tmproj
23+
.vscode/
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
apiVersion: v2
2+
name: cyberark-disco-agent
3+
description: |-
4+
The cyberark-disco-agent connects your Kubernetes or Openshift cluster to CyberArk Discovery and Context.
5+
6+
maintainers:
7+
- name: CyberArk
8+
9+
url: https://cyberark.com
10+
11+
sources:
12+
- https://github.com/jetstack/jetstack-secure
13+
14+
# These versions are meant to be overridden by `make helm-chart`. No `v` prefix
15+
# for the `version` because Helm doesn't support auto-determining the latest
16+
# version for OCI Helm charts that use a `v` prefix.
17+
version: 0.0.0
18+
appVersion: "v0.0.0"
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
- Check the application is running:
2+
> kubectl get pods -n {{ .Release.Namespace }} -l app.kubernetes.io/instance={{ .Release.Name }}
3+
4+
- Check the application logs for successful connection to the platform:
5+
> kubectl logs -n {{ .Release.Namespace }} -l app.kubernetes.io/instance={{ .Release.Name }}
Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,62 @@
1+
{{/*
2+
Expand the name of the chart.
3+
*/}}
4+
{{- define "cyberark-disco-agent.name" -}}
5+
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
6+
{{- end }}
7+
8+
{{/*
9+
Create a default fully qualified app name.
10+
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
11+
If release name contains chart name it will be used as a full name.
12+
*/}}
13+
{{- define "cyberark-disco-agent.fullname" -}}
14+
{{- if .Values.fullnameOverride }}
15+
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
16+
{{- else }}
17+
{{- $name := default .Chart.Name .Values.nameOverride }}
18+
{{- if contains $name .Release.Name }}
19+
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
20+
{{- else }}
21+
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
22+
{{- end }}
23+
{{- end }}
24+
{{- end }}
25+
26+
{{/*
27+
Create chart name and version as used by the chart label.
28+
*/}}
29+
{{- define "cyberark-disco-agent.chart" -}}
30+
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
31+
{{- end }}
32+
33+
{{/*
34+
Common labels
35+
*/}}
36+
{{- define "cyberark-disco-agent.labels" -}}
37+
helm.sh/chart: {{ include "cyberark-disco-agent.chart" . }}
38+
{{ include "cyberark-disco-agent.selectorLabels" . }}
39+
{{- if .Chart.AppVersion }}
40+
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
41+
{{- end }}
42+
app.kubernetes.io/managed-by: {{ .Release.Service }}
43+
{{- end }}
44+
45+
{{/*
46+
Selector labels
47+
*/}}
48+
{{- define "cyberark-disco-agent.selectorLabels" -}}
49+
app.kubernetes.io/name: {{ include "cyberark-disco-agent.name" . }}
50+
app.kubernetes.io/instance: {{ .Release.Name }}
51+
{{- end }}
52+
53+
{{/*
54+
Create the name of the service account to use
55+
*/}}
56+
{{- define "cyberark-disco-agent.serviceAccountName" -}}
57+
{{- if .Values.serviceAccount.create }}
58+
{{- default (include "cyberark-disco-agent.fullname" .) .Values.serviceAccount.name }}
59+
{{- else }}
60+
{{- default "default" .Values.serviceAccount.name }}
61+
{{- end }}
62+
{{- end }}
Lines changed: 75 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,75 @@
1+
apiVersion: v1
2+
kind: ConfigMap
3+
metadata:
4+
name: {{ include "cyberark-disco-agent.fullname" . }}-config
5+
namespace: {{ .Release.Namespace }}
6+
labels:
7+
{{- include "cyberark-disco-agent.labels" . | nindent 4 }}
8+
data:
9+
config.yaml: |-
10+
period: {{ .Values.config.period | quote }}
11+
{{- with .Values.config.excludeAnnotationKeysRegex }}
12+
exclude-annotation-keys-regex:
13+
{{- . | toYaml | nindent 6 }}
14+
{{- end }}
15+
{{- with .Values.config.excludeLabelKeysRegex }}
16+
exclude-label-keys-regex:
17+
{{- . | toYaml | nindent 6 }}
18+
{{- end }}
19+
data-gatherers:
20+
- kind: k8s-discovery
21+
name: ark/discovery
22+
- kind: k8s-dynamic
23+
name: ark/namespaces
24+
config:
25+
resource-type:
26+
version: v1
27+
resource: namespaces
28+
- kind: k8s-dynamic
29+
name: ark/serviceaccounts
30+
config:
31+
resource-type:
32+
resource: serviceaccounts
33+
version: v1
34+
- kind: k8s-dynamic
35+
name: ark/secrets
36+
config:
37+
resource-type:
38+
version: v1
39+
resource: secrets
40+
field-selectors:
41+
- type!=kubernetes.io/service-account-token
42+
- type!=kubernetes.io/dockercfg
43+
- type!=kubernetes.io/dockerconfigjson
44+
- type!=kubernetes.io/basic-auth
45+
- type!=kubernetes.io/ssh-auth
46+
- type!=bootstrap.kubernetes.io/token
47+
- type!=helm.sh/release.v1
48+
- kind: k8s-dynamic
49+
name: ark/roles
50+
config:
51+
resource-type:
52+
version: v1
53+
group: rbac.authorization.k8s.io
54+
resource: roles
55+
- kind: k8s-dynamic
56+
name: ark/clusterroles
57+
config:
58+
resource-type:
59+
version: v1
60+
group: rbac.authorization.k8s.io
61+
resource: clusterroles
62+
- kind: k8s-dynamic
63+
name: ark/rolebindings
64+
config:
65+
resource-type:
66+
version: v1
67+
group: rbac.authorization.k8s.io
68+
resource: rolebindings
69+
- kind: k8s-dynamic
70+
name: ark/clusterrolebindings
71+
config:
72+
resource-type:
73+
version: v1
74+
group: rbac.authorization.k8s.io
75+
resource: clusterrolebindings
Lines changed: 131 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,131 @@
1+
apiVersion: apps/v1
2+
kind: Deployment
3+
metadata:
4+
name: {{ include "cyberark-disco-agent.fullname" . }}
5+
labels:
6+
{{- include "cyberark-disco-agent.labels" . | nindent 4 }}
7+
spec:
8+
replicas: {{ .Values.replicaCount }}
9+
selector:
10+
matchLabels:
11+
{{- include "cyberark-disco-agent.selectorLabels" . | nindent 6 }}
12+
template:
13+
metadata:
14+
{{- with .Values.podAnnotations }}
15+
annotations:
16+
{{- toYaml . | nindent 8 }}
17+
{{- end }}
18+
labels:
19+
{{- include "cyberark-disco-agent.labels" . | nindent 8 }}
20+
{{- with .Values.podLabels }}
21+
{{- toYaml . | nindent 8 }}
22+
{{- end }}
23+
spec:
24+
{{- with .Values.imagePullSecrets }}
25+
imagePullSecrets:
26+
{{- toYaml . | nindent 8 }}
27+
{{- end }}
28+
serviceAccountName: {{ include "cyberark-disco-agent.serviceAccountName" . }}
29+
{{- with .Values.podSecurityContext }}
30+
securityContext:
31+
{{- toYaml . | nindent 8 }}
32+
{{- end }}
33+
containers:
34+
- name: {{ .Chart.Name }}
35+
{{- with .Values.securityContext }}
36+
securityContext:
37+
{{- toYaml . | nindent 12 }}
38+
{{- end }}
39+
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
40+
imagePullPolicy: {{ .Values.image.pullPolicy }}
41+
env:
42+
- name: POD_NAMESPACE
43+
valueFrom:
44+
fieldRef:
45+
fieldPath: metadata.namespace
46+
- name: POD_NAME
47+
valueFrom:
48+
fieldRef:
49+
fieldPath: metadata.name
50+
- name: POD_UID
51+
valueFrom:
52+
fieldRef:
53+
fieldPath: metadata.uid
54+
- name: POD_NODE
55+
valueFrom:
56+
fieldRef:
57+
fieldPath: spec.nodeName
58+
- name: ARK_USERNAME
59+
valueFrom:
60+
secretKeyRef:
61+
name: {{ .Values.authentication.secretName }}
62+
key: ARK_USERNAME
63+
- name: ARK_SECRET
64+
valueFrom:
65+
secretKeyRef:
66+
name: {{ .Values.authentication.secretName }}
67+
key: ARK_SECRET
68+
- name: ARK_PLATFORM_DOMAIN
69+
valueFrom:
70+
secretKeyRef:
71+
name: {{ .Values.authentication.secretName }}
72+
key: ARK_PLATFORM_DOMAIN
73+
- name: ARK_SUBDOMAIN
74+
valueFrom:
75+
secretKeyRef:
76+
name: {{ .Values.authentication.secretName }}
77+
key: ARK_SUBDOMAIN
78+
{{- with .Values.http_proxy }}
79+
- name: HTTP_PROXY
80+
value: {{ . }}
81+
{{- end }}
82+
{{- with .Values.https_proxy }}
83+
- name: HTTPS_PROXY
84+
value: {{ . }}
85+
{{- end }}
86+
{{- with .Values.no_proxy }}
87+
- name: NO_PROXY
88+
value: {{ . }}
89+
{{- end }}
90+
args:
91+
- "agent"
92+
- "-c"
93+
- "/etc/cyberark-disco-agent/config.yaml"
94+
- --machine-hub
95+
{{- if .Values.metrics.enabled }}
96+
- --enable-metrics
97+
{{- end }}
98+
{{- range .Values.extraArgs }}
99+
- {{ . | quote }}
100+
{{- end }}
101+
{{- with .Values.resources }}
102+
resources:
103+
{{- toYaml . | nindent 12 }}
104+
{{- end }}
105+
volumeMounts:
106+
- name: config
107+
mountPath: "/etc/cyberark-disco-agent"
108+
readOnly: true
109+
{{- with .Values.volumeMounts }}
110+
{{- toYaml . | nindent 12 }}
111+
{{- end }}
112+
volumes:
113+
- name: config
114+
configMap:
115+
name: {{ include "cyberark-disco-agent.fullname" . }}-config
116+
optional: false
117+
{{- with .Values.volumes }}
118+
{{- toYaml . | nindent 8 }}
119+
{{- end }}
120+
{{- with .Values.nodeSelector }}
121+
nodeSelector:
122+
{{- toYaml . | nindent 8 }}
123+
{{- end }}
124+
{{- with .Values.affinity }}
125+
affinity:
126+
{{- toYaml . | nindent 8 }}
127+
{{- end }}
128+
{{- with .Values.tolerations }}
129+
tolerations:
130+
{{- toYaml . | nindent 8 }}
131+
{{- end }}
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
{{- if .Values.podDisruptionBudget.enabled }}
2+
apiVersion: policy/v1
3+
kind: PodDisruptionBudget
4+
metadata:
5+
name: {{ include "cyberark-disco-agent.fullname" . }}
6+
namespace: {{ .Release.Namespace }}
7+
labels:
8+
{{- include "cyberark-disco-agent.labels" . | nindent 4 }}
9+
spec:
10+
selector:
11+
matchLabels:
12+
{{- include "cyberark-disco-agent.selectorLabels" . | nindent 6 }}
13+
14+
{{- if not (or (hasKey .Values.podDisruptionBudget "minAvailable") (hasKey .Values.podDisruptionBudget "maxUnavailable")) }}
15+
minAvailable: 1 # Default value because minAvailable and maxUnavailable are not set
16+
{{- end }}
17+
{{- if hasKey .Values.podDisruptionBudget "minAvailable" }}
18+
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
19+
{{- end }}
20+
{{- if hasKey .Values.podDisruptionBudget "maxUnavailable" }}
21+
maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }}
22+
{{- end }}
23+
{{- end }}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{{- if and .Values.metrics.enabled .Values.metrics.podmonitor.enabled }}
2+
apiVersion: monitoring.coreos.com/v1
3+
kind: PodMonitor
4+
metadata:
5+
name: {{ include "venafi-kubernetes-agent.fullname" . }}
6+
{{- if .Values.metrics.podmonitor.namespace }}
7+
namespace: {{ .Values.metrics.podmonitor.namespace }}
8+
{{- else }}
9+
namespace: {{ .Release.Namespace | quote }}
10+
{{- end }}
11+
labels:
12+
{{- include "venafi-kubernetes-agent.labels" . | nindent 4 }}
13+
prometheus: {{ .Values.metrics.podmonitor.prometheusInstance }}
14+
{{- with .Values.metrics.podmonitor.labels }}
15+
{{- toYaml . | nindent 4 }}
16+
{{- end }}
17+
{{- with .Values.metrics.podmonitor.annotations }}
18+
annotations:
19+
{{- toYaml . | nindent 4 }}
20+
{{- end }}
21+
spec:
22+
jobLabel: {{ include "venafi-kubernetes-agent.fullname" . }}
23+
selector:
24+
matchLabels:
25+
{{- include "venafi-kubernetes-agent.selectorLabels" . | nindent 6 }}
26+
{{- if .Values.metrics.podmonitor.namespace }}
27+
namespaceSelector:
28+
matchNames:
29+
- {{ .Release.Namespace | quote }}
30+
{{- end }}
31+
podMetricsEndpoints:
32+
- port: http-metrics
33+
path: /metrics
34+
interval: {{ .Values.metrics.podmonitor.interval }}
35+
scrapeTimeout: {{ .Values.metrics.podmonitor.scrapeTimeout }}
36+
honorLabels: {{ .Values.metrics.podmonitor.honorLabels }}
37+
{{- with .Values.metrics.podmonitor.endpointAdditionalProperties }}
38+
{{- toYaml . | nindent 4 }}
39+
{{- end }}
40+
{{- end }}

0 commit comments

Comments
 (0)