Skip to content

Commit

Permalink
Generate openshift4 golden tests
Browse files Browse the repository at this point in the history
  • Loading branch information
bastjan committed Nov 9, 2023
1 parent d34e9d1 commit b6656f4
Show file tree
Hide file tree
Showing 11 changed files with 257 additions and 3 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
apiVersion: apps/v1
kind: Deployment
metadata:
labels:
app.kubernetes.io/component: exporter
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: exporter
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: deployment
app.kubernetes.io/part-of: alerts-exporter
control-plane: alerts-exporter
name: alerts-exporter
namespace: appuio-alerts-exporter
spec:
replicas: 1
selector:
matchLabels:
control-plane: alerts-exporter
template:
metadata:
annotations:
kubectl.kubernetes.io/default-container: exporter
labels:
control-plane: alerts-exporter
spec:
containers:
- args:
- --listen-addr=127.0.0.1:8080
- --tls
- --host=alertmanager-operated.openshift-monitoring.svc.cluster.local:9095
- --tls-server-name=alertmanager-main.openshift-monitoring.svc.cluster.local
- --k8s-bearer-token-auth
- --tls-ca-cert=/etc/ssl/certs/serving-certs/service-ca.crt
image: ghcr.io/appuio/alerts_exporter:latest
name: exporter
resources:
limits:
cpu: 100m
memory: 128Mi
requests:
cpu: 10m
memory: 64Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
volumeMounts:
- mountPath: /etc/ssl/certs/serving-certs/
name: ca-bundle
readOnly: true
- args:
- --secure-listen-address=0.0.0.0:8443
- --upstream=http://127.0.0.1:8080/
- --logtostderr=true
- --v=0
image: gcr.io/kubebuilder/kube-rbac-proxy:v0.14.1
name: kube-rbac-proxy
ports:
- containerPort: 8443
name: https
protocol: TCP
resources:
limits:
cpu: 500m
memory: 128Mi
requests:
cpu: 10m
memory: 64Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
serviceAccountName: alerts-exporter
terminationGracePeriodSeconds: 10
volumes:
- configMap:
defaultMode: 288
name: openshift-service-ca.crt
name: ca-bundle
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
labels:
app.kubernetes.io/component: metrics
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: alerts-exporter-metrics-monitor
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: servicemonitor
app.kubernetes.io/part-of: alerts-exporter
control-plane: alerts-exporter
name: alerts-exporter-metrics-monitor
namespace: appuio-alerts-exporter
spec:
endpoints:
- bearerTokenFile: /var/run/secrets/kubernetes.io/serviceaccount/token
metricRelabelings:
- action: keep
regex: alerts_exporter_.+
sourceLabels:
- __name__
path: /metrics
port: https
scheme: https
tlsConfig:
insecureSkipVerify: true
selector:
matchLabels:
control-plane: alerts-exporter
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
app.kubernetes.io/managed-by: commodore
name: exporter-role
rules:
- apiGroups:
- monitoring.coreos.com
resources:
- alertmanagers
verbs:
- patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
app.kubernetes.io/component: kube-rbac-proxy
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: metrics-reader
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: clusterrole
app.kubernetes.io/part-of: alerts-exporter
name: metrics-reader
rules:
- nonResourceURLs:
- /metrics
verbs:
- get
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
app.kubernetes.io/component: kube-rbac-proxy
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: proxy-role
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: clusterrole
app.kubernetes.io/part-of: alerts-exporter
name: proxy-role
rules:
- apiGroups:
- authentication.k8s.io
resources:
- tokenreviews
verbs:
- create
- apiGroups:
- authorization.k8s.io
resources:
- subjectaccessreviews
verbs:
- create
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
labels:
app.kubernetes.io/component: rbac
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: exporter-rolebinding
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: clusterrolebinding
app.kubernetes.io/part-of: alerts-exporter
name: exporter-rolebinding
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: exporter-role
subjects:
- kind: ServiceAccount
name: alerts-exporter
namespace: appuio-alerts-exporter
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
labels:
app.kubernetes.io/component: kube-rbac-proxy
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: proxy-rolebinding
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: clusterrolebinding
app.kubernetes.io/part-of: alerts-exporter
name: proxy-rolebinding
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: proxy-role
subjects:
- kind: ServiceAccount
name: alerts-exporter
namespace: appuio-alerts-exporter
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
apiVersion: v1
kind: Namespace
metadata:
annotations:
openshift.io/node-selector: node-role.kubernetes.io/infra=
labels:
app.kubernetes.io/component: exporter
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: exporter
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: namespace
app.kubernetes.io/part-of: alerts-exporter
control-plane: alerts-exporter
openshift.io/cluster-monitoring: "true"
name: appuio-alerts-exporter
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
apiVersion: v1
kind: Service
metadata:
labels:
app.kubernetes.io/component: kube-rbac-proxy
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: alerts-exporter-metrics-service
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: service
app.kubernetes.io/part-of: alerts-exporter
control-plane: alerts-exporter
name: alerts-exporter-metrics-service
namespace: appuio-alerts-exporter
spec:
ports:
- name: https
port: 8443
protocol: TCP
targetPort: https
selector:
control-plane: alerts-exporter
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
apiVersion: v1
kind: ServiceAccount
metadata:
labels:
app.kubernetes.io/component: rbac
app.kubernetes.io/created-by: alerts-exporter
app.kubernetes.io/instance: alerts-exporter
app.kubernetes.io/managed-by: commodore
app.kubernetes.io/name: serviceaccount
app.kubernetes.io/part-of: alerts-exporter
name: alerts-exporter
namespace: appuio-alerts-exporter
7 changes: 4 additions & 3 deletions tests/openshift4.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Overwrite parameters here

# parameters: {...}
parameters:
alerts_exporter:
manifests:
subdir: config/openshift4

0 comments on commit b6656f4

Please sign in to comment.