Skip to content

Commit 4f8dc08

Browse files
authored
Merge branch 'dev' into container-registry.zalando.net/teapot/skipper-internal
2 parents f763218 + bf56424 commit 4f8dc08

File tree

14 files changed

+124
-68
lines changed

14 files changed

+124
-68
lines changed

cluster/config-defaults.yaml

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ karpenter_instance_family_t_enabled: "false"
5555
karpenter_enable_spot: "true"
5656

5757
# ALB config created by kube-aws-ingress-controller
58-
kube_aws_ingress_controller_ssl_policy: "ELBSecurityPolicy-TLS13-1-2-2021-06"
58+
kube_aws_ingress_controller_ssl_policy: "ELBSecurityPolicy-TLS13-1-2-Res-2021-06"
5959
kube_aws_ingress_controller_idle_timeout: "1m"
6060
kube_aws_ingress_controller_deregistration_delay_timeout: "10s"
6161
# allow using NLBs for ingress
@@ -377,6 +377,11 @@ skipper_open_policy_agent_data_preprocessing_optimization_enabled: "false"
377377
# Default timeout value in seconds for outgoing http calls from Open Policy Agent in a skipper filter
378378
skipper_open_policy_agent_styra_response_header_timeout: "2"
379379

380+
# Decision logging use event buffer type
381+
skipper_open_policy_agent_decision_logs_buffer_type_event_enable: "false"
382+
# Decision logging sets the maximum number of decision log events that can be buffered before being dropped
383+
skipper_open_policy_agent_decision_logs_buffer_type_event_limit: "1000"
384+
380385
#
381386
# FabricGateway controller config
382387
#
@@ -1293,4 +1298,4 @@ aws_load_balancer_controller_cpu: "100m"
12931298
aws_load_balancer_controller_mem_max: "4Gi"
12941299

12951300
# configure if sandbox-controller should be deployed
1296-
sandbox_controller_enabled: "false"
1301+
sandbox_controller_enabled: "false"

cluster/manifests/02-skipper-validation-webhook/deployment.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ spec:
3232
priorityClassName: system-cluster-critical
3333
containers:
3434
- name: skipper-admission-webhook
35-
image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.52
35+
image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.63
3636
args:
3737
- webhook
3838
- --address=:9085

cluster/manifests/deployment-service/controller-statefulset.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ spec:
2929
terminationGracePeriodSeconds: 300
3030
containers:
3131
- name: "deployment-service-controller"
32-
image: "container-registry.zalando.net/teapot/deployment-controller:master-266"
32+
image: "container-registry.zalando.net/teapot/deployment-controller:master-268"
3333
args:
3434
- "--config-namespace=kube-system"
3535
- "--decrypt-kms-alias-arn=arn:aws:kms:{{ .Cluster.Region }}:{{ .Cluster.InfrastructureAccountID }}:alias/deployment-secret"

cluster/manifests/deployment-service/status-service-deployment.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# {{ $image := "container-registry.zalando.net/teapot/deployment-status-service:master-266" }}
1+
# {{ $image := "container-registry.zalando.net/teapot/deployment-status-service:master-268" }}
22
# {{ $version := index (split $image ":") 1 }}
33

44
apiVersion: apps/v1

cluster/manifests/ingress-controller/deployment.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# {{ $image := "926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/kube-ingress-aws-controller:v0.17.7" }}
1+
# {{ $image := "926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/kube-ingress-aws-controller:v0.18.3" }}
22
# {{ $version := index (split $image ":") 1 }}
33

44
apiVersion: apps/v1

cluster/manifests/roles/kubernetes-resource-analyzer.yaml

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,3 +13,36 @@ subjects:
1313
- apiGroup: rbac.authorization.k8s.io
1414
kind: User
1515
name: zalando-iam:zalando:service:stups_kubernetes
16+
---
17+
apiVersion: rbac.authorization.k8s.io/v1
18+
kind: ClusterRole
19+
metadata:
20+
name: kubernetes-resource-analyzer-secrets
21+
labels:
22+
application: kubernetes
23+
component: resource-analyzer
24+
rules:
25+
- apiGroups:
26+
- ""
27+
resources:
28+
- secrets
29+
verbs:
30+
- get
31+
- list
32+
- watch
33+
---
34+
apiVersion: rbac.authorization.k8s.io/v1
35+
kind: ClusterRoleBinding
36+
metadata:
37+
name: kubernetes-resource-analyzer-secrets
38+
labels:
39+
application: kubernetes
40+
component: resource-analyzer
41+
roleRef:
42+
apiGroup: rbac.authorization.k8s.io
43+
kind: ClusterRole
44+
name: kubernetes-resource-analyzer-secrets
45+
subjects:
46+
- apiGroup: rbac.authorization.k8s.io
47+
kind: User
48+
name: zalando-iam:zalando:service:stups_kubernetes

cluster/manifests/sandbox-controller/30-deployment.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# {{ $image := "container-registry.zalando.net/gwproxy/sandbox-controller:main-13" }}
1+
# {{ $image := "container-registry.zalando.net/gwproxy/sandbox-controller:main-16" }}
22
# {{ $version := index (split $image ":") 1 }}
33

44
{{ if eq .Cluster.ConfigItems.sandbox_controller_enabled "true" }}

cluster/manifests/skipper/configmap-open-policy-agent.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,12 @@ data:
3131
session_name: open-policy-agent-instance
3232
name: styra-bundles
3333
url: "{{ .Cluster.ConfigItems.skipper_open_policy_agent_bundles_url }}"
34+
{{ if eq .Cluster.ConfigItems.skipper_open_policy_agent_decision_logs_buffer_type_event_enable "true" }}
35+
decision_logs:
36+
reporting:
37+
buffer_type: "event"
38+
buffer_size_limit_events: {{ .Cluster.ConfigItems.skipper_open_policy_agent_decision_logs_buffer_type_event_limit }}
39+
{{ end }}
3440
envoymetadata.json: |-
3541
{
3642
"filter_metadata": {

cluster/manifests/stackset-controller/deployment.yaml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
{{ $version := "v1.4.99" }}
1+
{{ $version := "v1.4.112" }}
22
apiVersion: apps/v1
33
kind: Deployment
44
metadata:
@@ -55,8 +55,10 @@ spec:
5555
- "--sync-ingress-annotation=zalando.org/aws-waf-web-acl-id"
5656
- "--sync-ingress-annotation=kubernetes.io/ingress.class"
5757
{{ end}}
58-
- "--cluster-domain={{ .Values.hosted_zone }}"
5958
- "--cluster-domain=ingress.cluster.local"
59+
{{- if eq .Cluster.Provider "zalando-aws" }}
60+
- "--cluster-domain={{ .Values.hosted_zone }}"
61+
{{- end }}
6062
resources:
6163
limits:
6264
cpu: 10m

cluster/node-pools/master-default/userdata.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -260,7 +260,7 @@ write_files:
260260
name: admission-controller-kubeconfig
261261
readOnly: true
262262
- name: skipper-admission-webhook
263-
image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.53
263+
image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.63
264264
args:
265265
- webhook
266266
- --address=:9085
@@ -437,7 +437,7 @@ write_files:
437437
value: {{ .Cluster.ConfigItems.apiserver_business_partner_ids }}
438438
{{ end }}
439439
- name: skipper-proxy
440-
image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.53
440+
image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.63
441441
args:
442442
- skipper
443443
- -access-log-strip-query
@@ -488,7 +488,7 @@ write_files:
488488
name: ssl-certs-kubernetes
489489
readOnly: true
490490
- name: skipper-metrics
491-
image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.53
491+
image: 926694233939.dkr.ecr.eu-central-1.amazonaws.com/production_namespace/teapot/skipper:v0.22.63
492492
args:
493493
- skipper
494494
- -access-log-strip-query

0 commit comments

Comments
 (0)