diff --git a/.github/actions/test-charts/action.yml b/.github/actions/test-charts/action.yml index 1f4c0fccb..2c3bb37c6 100644 --- a/.github/actions/test-charts/action.yml +++ b/.github/actions/test-charts/action.yml @@ -190,9 +190,8 @@ runs: env: SONATAFLOW_OPERATOR_VERSION: "10.1.0" run: | - for crdDir in charts/orchestrator-infra/crds/*; do - kubectl create -f "${crdDir}" - done + kubectl create -f charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml + kubectl create -f charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml kubectl create -f "https://github.com/apache/incubator-kie-tools/releases/download/${SONATAFLOW_OPERATOR_VERSION}/apache-kie-${SONATAFLOW_OPERATOR_VERSION}-incubating-sonataflow-operator.yaml" - name: Set up external services and test resources for rhdh diff --git a/charts/orchestrator-infra/Chart.yaml b/charts/orchestrator-infra/Chart.yaml index ee2f999f0..de9f53b2d 100644 --- a/charts/orchestrator-infra/Chart.yaml +++ b/charts/orchestrator-infra/Chart.yaml @@ -14,4 +14,4 @@ maintainers: type: application sources: - https://github.com/redhat-developer/rhdh-chart -version: 0.6.1 +version: 0.7.0 diff --git a/charts/orchestrator-infra/README.md b/charts/orchestrator-infra/README.md index 8492219d4..f5c824bbe 100644 --- a/charts/orchestrator-infra/README.md +++ b/charts/orchestrator-infra/README.md @@ -1,7 +1,7 @@ # Orchestrator Infra Chart for OpenShift -![Version: 0.6.1](https://img.shields.io/badge/Version-0.6.1-informational?style=flat-square) +![Version: 0.7.0](https://img.shields.io/badge/Version-0.7.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) Helm chart to deploy the Orchestrator solution's required infrastructure suite on OpenShift, including OpenShift Serverless Operator and OpenShift Serverless Logic Operator, both required to configure Red Hat Developer Hub to use the Orchestrator. @@ -25,7 +25,7 @@ Kubernetes: `>= 1.25.0-0` ```console helm repo add redhat-developer https://redhat-developer.github.io/rhdh-chart -helm install my-orchestrator-infra redhat-developer/redhat-developer-hub-orchestrator-infra --version 0.6.1 +helm install my-orchestrator-infra redhat-developer/redhat-developer-hub-orchestrator-infra --version 0.7.0 ``` > **Tip**: List all releases using `helm list` @@ -83,6 +83,10 @@ The command removes all the Kubernetes components associated with the chart and | Key | Description | Type | Default | |-----|-------------|------|---------| +| olm.catalog.selector | ClusterCatalog selector for OLM v1 ClusterExtension resources | object | `{"matchLabels":{"olm.operatorframework.io/metadata.name":"openshift-redhat-operators"}}` | +| olmVersion | OLM API version to use for operator installation (`v0` or `v1`) | string | `"v0"` | +| serverlessLogicOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-logic-operator-installer"` | +| serverlessLogicOperator.createNamespace | whether to create the operator namespace (set to false if namespace already exists) | bool | `true` | | serverlessLogicOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessLogicOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless-logic"` | | serverlessLogicOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | @@ -91,6 +95,8 @@ The command removes all the Kubernetes components associated with the chart and | serverlessLogicOperator.subscription.spec.source | name of the catalog source | string | `"redhat-operators"` | | serverlessLogicOperator.subscription.spec.sourceNamespace | | string | `"openshift-marketplace"` | | serverlessLogicOperator.subscription.spec.startingCSV | The initial version of the operator, must match CRDs installed by the chart | string | `"logic-operator.v1.38.0"` | +| serverlessOperator.clusterExtension.serviceAccount.name | service account used by OLM v1 to install the operator | string | `"serverless-operator-installer"` | +| serverlessOperator.createNamespace | whether to create the operator namespace (set to false if namespace already exists) | bool | `true` | | serverlessOperator.enabled | whether the operator should be deployed by the chart | bool | `true` | | serverlessOperator.subscription.namespace | namespace where the operator should be deployed | string | `"openshift-serverless"` | | serverlessOperator.subscription.spec.channel | channel of an operator package to subscribe to | string | `"stable"` | @@ -101,6 +107,18 @@ The command removes all the Kubernetes components associated with the chart and | tests.enabled | Whether to create the test pod used for testing the Release using `helm test`. | bool | `true` | | tests.image | Test pod image | string | `"bitnami/kubectl:latest"` | +### OLM v0 and OLM v1 operator installation + +The chart defaults to `olmVersion: v0`. + +- `v0`: creates `Subscription` resources +- `v1`: creates `ClusterExtension` resources with an installer ServiceAccount and ClusterRoleBinding + +```bash +helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 +helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 +``` + ### Installing Knative Eventing and Knative Serving CRDs The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand. @@ -116,5 +134,3 @@ podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1b podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml ``` - -After running these commands, you may need to re-add the `helm.sh/hook` annotations. diff --git a/charts/orchestrator-infra/README.md.gotmpl b/charts/orchestrator-infra/README.md.gotmpl index 233313048..17e569932 100644 --- a/charts/orchestrator-infra/README.md.gotmpl +++ b/charts/orchestrator-infra/README.md.gotmpl @@ -76,12 +76,24 @@ The command removes all the Kubernetes components associated with the chart and {{ template "chart.valuesSection" . }} +### OLM v0 and OLM v1 operator installation + +The chart defaults to `olmVersion: v0`. + +- `v0`: creates `Subscription` resources +- `v1`: creates `ClusterExtension` resources with an installer ServiceAccount and ClusterRoleBinding + +```bash +helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v0 +helm install my-orchestrator-infra ./charts/orchestrator-infra --set olmVersion=v1 +``` + ### Installing Knative Eventing and Knative Serving CRDs The orchestrator-infra chart requires several CRDs for Knative Eventing and Knative Serving. These CRDs will be applied prior to installing the chart, ensuring that Knative CRs can be created as part of the chart's deployment process. This approach eliminates the need to wait for the OpenShift Serverless Operator's subscription to install them beforehand. The KnativeEventing and KnativeServing CRDs are required for this chart to run. These CRDs need to be present under the `crds/` directory before running `helm install`. -After installing the openshift-serverless subscription, more Knative CRDs will be installed on the cluster. +After installing the openshift-serverless subscription, more Knative CRDs will be installed on the cluster. The versions of the CRDs present in the chart and the ones in the subscription must match. In order to verify the correct CRD, use this following command to extract the CRD: @@ -91,5 +103,3 @@ podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1b podman container run --rm --entrypoint cat "$osl_bundle" /manifests/operator_v1beta1_knativeserving_crd.yaml > crds/knative-serving/knative-serving-crd.yaml ``` - -After running these commands, you may need to re-add the `helm.sh/hook` annotations. diff --git a/charts/orchestrator-infra/ci/upstream-olm-values.yaml b/charts/orchestrator-infra/ci/upstream-olm-values.yaml index 6dafe01f1..52a7c9022 100644 --- a/charts/orchestrator-infra/ci/upstream-olm-values.yaml +++ b/charts/orchestrator-infra/ci/upstream-olm-values.yaml @@ -1,11 +1,13 @@ serverlessLogicOperator: enabled: true + createNamespace: false subscription: namespace: operators spec: sourceNamespace: olm serverlessOperator: + createNamespace: false subscription: namespace: operators spec: diff --git a/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml b/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml index ee3bbfd24..52951f00a 100644 --- a/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml +++ b/charts/orchestrator-infra/crds/knative-eventing/knative-eventing-crd.yaml @@ -16,10 +16,6 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: name: knativeeventings.operator.knative.dev - annotations: - "helm.sh/hook": pre-delete - "helm.sh/hook-weight": "-10" - "helm.sh/hook-delete-policy": before-hook-creation labels: app.kubernetes.io/version: devel app.kubernetes.io/name: knative-operator diff --git a/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml b/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml index 3a316a833..21bc0a70b 100644 --- a/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml +++ b/charts/orchestrator-infra/crds/knative-serving/knative-serving-crd.yaml @@ -16,10 +16,6 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: name: knativeservings.operator.knative.dev - annotations: - "helm.sh/hook": pre-delete - "helm.sh/hook-weight": "-10" - "helm.sh/hook-delete-policy": before-hook-creation labels: app.kubernetes.io/version: devel app.kubernetes.io/name: knative-operator diff --git a/charts/orchestrator-infra/templates/NOTES.txt b/charts/orchestrator-infra/templates/NOTES.txt index 1897ccb63..b3b890707 100644 --- a/charts/orchestrator-infra/templates/NOTES.txt +++ b/charts/orchestrator-infra/templates/NOTES.txt @@ -4,18 +4,11 @@ Helm Release {{ .Release.Name }} installed in namespace {{ .Release.Namespace }} {{- $yes := "YES" }} {{- $no := "NO " }} {{- $serverlessOperatorInstalled := $no }} -{{- $knativeServingInstalled := $no }} -{{- $knativeEventingInstalled := $no }} {{- $serverlessLogicOperatorInstalled := $no }} -{{- $sonataFlowPlatformInstalled := $no }} -{{- $timeout := "--timeout=5m" }} {{- if .Values.serverlessOperator.enabled }} -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace "serverless-operator" .Release.Name .Capabilities.APIVersions ) }} -{{- if eq $unmanagedSubscriptionExists "false" }} {{- $serverlessOperatorInstalled = $yes }} {{- end }} -{{- end }} {{- if .Values.serverlessLogicOperator.enabled }} {{- $serverlessLogicOperatorInstalled = $yes }} diff --git a/charts/orchestrator-infra/templates/_helpers.tpl b/charts/orchestrator-infra/templates/_helpers.tpl index 5db6043ee..d6f877580 100644 --- a/charts/orchestrator-infra/templates/_helpers.tpl +++ b/charts/orchestrator-infra/templates/_helpers.tpl @@ -1,37 +1,13 @@ {{/* Helper functions */}} -{{- define "unmanaged-resource-exists" -}} - {{- $api := index . 0 -}} - {{- $kind := index . 1 -}} - {{- $namespace := index . 2 -}} - {{- $name := index . 3 -}} - {{- $releaseName := index . 4 -}} - {{- $apiCapabilities := index . 5 -}} - {{- $unmanagedSubscriptionExists := "true" -}} - {{- if $apiCapabilities.Has (printf "%s/%s" $api $kind) }} - {{- $existingOperator := lookup $api $kind $namespace $name -}} - {{- if empty $existingOperator -}} - {{- "false" -}} - {{- else -}} - {{- $isManagedResource := include "is-managed-resource" (list $existingOperator $releaseName) -}} - {{- if eq $isManagedResource "true" -}} - {{- "false" -}} - {{- else -}} - {{- "true" -}} - {{- end -}} - {{- end -}} - {{- else -}} - {{- "false" -}} - {{- end -}} +{{- define "olm-version" -}} + {{- $requested := default "v0" .Values.olmVersion -}} + {{- $requested -}} {{- end -}} -{{- define "is-managed-resource" -}} - {{- $resource := index . 0 -}} - {{- $releaseName := index . 1 -}} - {{- $resourceReleaseName := dig "metadata" "annotations" (dict "meta.helm.sh/release-name" "NA") $resource -}} - {{- if eq (get $resourceReleaseName "meta.helm.sh/release-name") $releaseName -}} - {{- "true" -}} - {{- else -}} - {{- "false" -}} - {{- end -}} -{{- end -}} \ No newline at end of file +{{- define "csv-version" -}} + {{- $csv := index . 0 -}} + {{- $packageName := index . 1 -}} + {{- $version := trimPrefix (printf "%s." $packageName) $csv -}} + {{- trimPrefix "v" $version -}} +{{- end -}} diff --git a/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml new file mode 100644 index 000000000..235e377cb --- /dev/null +++ b/charts/orchestrator-infra/templates/serverless-logic/clusterextension.yaml @@ -0,0 +1,55 @@ +{{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}} +{{- $namespace := .Values.serverlessLogicOperator.subscription.namespace -}} +{{- $serviceAccountName := .Values.serverlessLogicOperator.clusterExtension.serviceAccount.name -}} +{{- if and (eq (include "olm-version" .) "v1") .Values.serverlessLogicOperator.enabled }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ $serviceAccountName }} + namespace: {{ $namespace }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ $packageName }}-installer-binding + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: + - kind: ServiceAccount + name: {{ $serviceAccountName }} + namespace: {{ $namespace }} +--- +apiVersion: olm.operatorframework.io/v1 +kind: ClusterExtension +metadata: + name: {{ $packageName }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +spec: + install: + preflight: + crdUpgradeSafety: + enforcement: None + namespace: {{ $namespace }} + serviceAccount: + name: {{ $serviceAccountName }} + source: + sourceType: Catalog + catalog: + packageName: {{ $packageName }} + channels: + - {{ .Values.serverlessLogicOperator.subscription.spec.channel }} + version: {{ include "csv-version" (list .Values.serverlessLogicOperator.subscription.spec.startingCSV $packageName) | quote }} + selector: + {{- toYaml .Values.olm.catalog.selector | nindent 8 }} + upgradeConstraintPolicy: CatalogProvided +{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml index 85a40de94..326b38cd3 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/namespace.yaml @@ -1,8 +1,9 @@ -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessLogicOperator.subscription.namespace .Release.Name .Capabilities.APIVersions) }} -{{- if and (eq $unmanagedNamespaceExists "false") .Values.serverlessLogicOperator.enabled }} +{{- if and .Values.serverlessLogicOperator.enabled .Values.serverlessLogicOperator.createNamespace (ne .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessOperator.subscription.namespace) }} --- apiVersion: v1 kind: Namespace metadata: name: {{ .Values.serverlessLogicOperator.subscription.namespace }} + annotations: + "helm.sh/resource-policy": keep {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless-logic/operator-group.yaml b/charts/orchestrator-infra/templates/serverless-logic/operator-group.yaml index 6334b5731..9e4d9da4c 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/operator-group.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/operator-group.yaml @@ -1,4 +1,4 @@ -{{- if .Values.serverlessLogicOperator.enabled }} +{{- if and .Values.serverlessLogicOperator.enabled (eq (include "olm-version" .) "v0") }} apiVersion: operators.coreos.com/v1 kind: OperatorGroup metadata: diff --git a/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml b/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml index 9980da02d..aa0b3ca2f 100644 --- a/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml +++ b/charts/orchestrator-infra/templates/serverless-logic/subscription.yaml @@ -1,10 +1,11 @@ -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessLogicOperator.subscription.namespace .Values.serverlessLogicOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions ) }} -{{- if and (eq $unmanagedSubscriptionExists "false") .Values.serverlessLogicOperator.enabled }} +{{- $packageName := .Values.serverlessLogicOperator.subscription.spec.name -}} +{{- $subscriptionNamespace := .Values.serverlessLogicOperator.subscription.namespace -}} +{{- if and (eq (include "olm-version" .) "v0") .Values.serverlessLogicOperator.enabled }} apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: - name: {{ .Values.serverlessLogicOperator.subscription.spec.name }} - namespace: {{ .Values.serverlessLogicOperator.subscription.namespace }} + name: {{ $packageName }} + namespace: {{ $subscriptionNamespace }} spec: {{- toYaml .Values.serverlessLogicOperator.subscription.spec | nindent 2 }} {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/clusterextension.yaml b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml new file mode 100644 index 000000000..5c4344bbc --- /dev/null +++ b/charts/orchestrator-infra/templates/serverless/clusterextension.yaml @@ -0,0 +1,54 @@ +{{- $packageName := .Values.serverlessOperator.subscription.spec.name -}} +{{- $namespace := .Values.serverlessOperator.subscription.namespace -}} +{{- $serviceAccountName := .Values.serverlessOperator.clusterExtension.serviceAccount.name -}} +{{- if and (eq (include "olm-version" .) "v1") .Values.serverlessOperator.enabled }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ $serviceAccountName }} + namespace: {{ $namespace }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ $packageName }}-installer-binding + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: + - kind: ServiceAccount + name: {{ $serviceAccountName }} + namespace: {{ $namespace }} +--- +apiVersion: olm.operatorframework.io/v1 +kind: ClusterExtension +metadata: + name: {{ $packageName }} + annotations: + meta.helm.sh/release-name: {{ .Release.Name }} + meta.helm.sh/release-namespace: {{ .Release.Namespace }} +spec: + install: + preflight: + crdUpgradeSafety: + enforcement: None + namespace: {{ $namespace }} + serviceAccount: + name: {{ $serviceAccountName }} + source: + sourceType: Catalog + catalog: + packageName: {{ $packageName }} + channels: + - {{ .Values.serverlessOperator.subscription.spec.channel }} + selector: + {{- toYaml .Values.olm.catalog.selector | nindent 8 }} + upgradeConstraintPolicy: CatalogProvided +{{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/knatives.yaml b/charts/orchestrator-infra/templates/serverless/knatives.yaml index 630a97afb..7aaf1273b 100644 --- a/charts/orchestrator-infra/templates/serverless/knatives.yaml +++ b/charts/orchestrator-infra/templates/serverless/knatives.yaml @@ -1,6 +1,4 @@ {{- if .Values.serverlessOperator.enabled }} -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" "knative-serving" .Release.Name .Capabilities.APIVersions) }} -{{- if eq $unmanagedNamespaceExists "false" }} --- apiVersion: v1 kind: Namespace @@ -10,10 +8,6 @@ metadata: "helm.sh/hook": pre-install "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep -{{- end }} - -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" "knative-eventing" .Release.Name .Capabilities.APIVersions) }} -{{- if eq $unmanagedNamespaceExists "false" }} --- apiVersion: v1 kind: Namespace @@ -23,10 +17,7 @@ metadata: "helm.sh/hook": pre-install "helm.sh/hook-weight": "-5" "helm.sh/resource-policy": keep -{{- end }} -{{- $unmanagedKnativeEventingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeEventing" "knative-eventing" "knative-eventing" .Release.Name .Capabilities.APIVersions) }} -{{- if eq $unmanagedKnativeEventingExists "false" }} --- apiVersion: operator.knative.dev/v1beta1 kind: KnativeEventing @@ -34,11 +25,7 @@ metadata: name: knative-eventing namespace: knative-eventing spec: - Registry: -{{- end }} - -{{- $unmanagedKnativeServingExists := include "unmanaged-resource-exists" (list "operator.knative.dev/v1beta1" "KnativeServing" "knative-serving" "knative-serving" .Release.Name .Capabilities.APIVersions) }} -{{- if eq $unmanagedKnativeServingExists "false" }} + Registry: {} --- apiVersion: operator.knative.dev/v1beta1 kind: KnativeServing @@ -50,6 +37,4 @@ spec: name: "" type: "" registry: {} - -{{- end }} {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/namespace.yaml b/charts/orchestrator-infra/templates/serverless/namespace.yaml index cf7cba3ba..bd2552da7 100644 --- a/charts/orchestrator-infra/templates/serverless/namespace.yaml +++ b/charts/orchestrator-infra/templates/serverless/namespace.yaml @@ -1,9 +1,10 @@ -{{- $unmanagedNamespaceExists := include "unmanaged-resource-exists" (list "v1" "Namespace" "" .Values.serverlessOperator.subscription.namespace .Release.Name .Capabilities.APIVersions) }} -{{- if and (eq $unmanagedNamespaceExists "false") .Values.serverlessOperator.enabled }} +{{- if and .Values.serverlessOperator.enabled .Values.serverlessOperator.createNamespace }} --- apiVersion: v1 kind: Namespace metadata: name: {{ .Values.serverlessOperator.subscription.namespace }} + annotations: + "helm.sh/resource-policy": keep {{- end }} diff --git a/charts/orchestrator-infra/templates/serverless/operator-group.yaml b/charts/orchestrator-infra/templates/serverless/operator-group.yaml index aeb7d3d7a..01764aea5 100644 --- a/charts/orchestrator-infra/templates/serverless/operator-group.yaml +++ b/charts/orchestrator-infra/templates/serverless/operator-group.yaml @@ -1,4 +1,4 @@ -{{- if .Values.serverlessOperator.enabled }} +{{- if and .Values.serverlessOperator.enabled (eq (include "olm-version" .) "v0") }} apiVersion: operators.coreos.com/v1 kind: OperatorGroup metadata: diff --git a/charts/orchestrator-infra/templates/serverless/subscription.yaml b/charts/orchestrator-infra/templates/serverless/subscription.yaml index 00fed973d..18d298d05 100644 --- a/charts/orchestrator-infra/templates/serverless/subscription.yaml +++ b/charts/orchestrator-infra/templates/serverless/subscription.yaml @@ -1,10 +1,11 @@ -{{- $unmanagedSubscriptionExists := include "unmanaged-resource-exists" (list "operators.coreos.com/v1alpha1" "Subscription" .Values.serverlessOperator.subscription.namespace .Values.serverlessOperator.subscription.spec.name .Release.Name .Capabilities.APIVersions ) }} -{{- if and (eq $unmanagedSubscriptionExists "false") .Values.serverlessOperator.enabled }} +{{- $packageName := .Values.serverlessOperator.subscription.spec.name -}} +{{- $subscriptionNamespace := .Values.serverlessOperator.subscription.namespace -}} +{{- if and (eq (include "olm-version" .) "v0") .Values.serverlessOperator.enabled }} apiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: - name: {{ .Values.serverlessOperator.subscription.spec.name }} - namespace: {{ .Values.serverlessOperator.subscription.namespace }} + name: {{ $packageName }} + namespace: {{ $subscriptionNamespace }} spec: {{- toYaml .Values.serverlessOperator.subscription.spec | nindent 2 }} {{- end }} diff --git a/charts/orchestrator-infra/templates/tests/infra-test.yaml b/charts/orchestrator-infra/templates/tests/infra-test.yaml index d4f5f4d5b..2fd9d64aa 100644 --- a/charts/orchestrator-infra/templates/tests/infra-test.yaml +++ b/charts/orchestrator-infra/templates/tests/infra-test.yaml @@ -68,6 +68,36 @@ roleRef: name: test-role-osl apiGroup: rbac.authorization.k8s.io --- +{{- if eq (include "olm-version" .) "v1" }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: test-role-clusterextensions + annotations: + helm.sh/hook: test + helm.sh/hook-delete-policy: before-hook-creation, hook-succeeded, hook-failed +rules: + - apiGroups: ["olm.operatorframework.io"] + resources: ["clusterextensions"] + verbs: ["list", "get"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: test-role-binding-clusterextensions + annotations: + helm.sh/hook: test + helm.sh/hook-delete-policy: before-hook-creation, hook-succeeded, hook-failed +subjects: + - kind: ServiceAccount + name: test-service-account + namespace: {{ .Release.Namespace }} +roleRef: + kind: ClusterRole + name: test-role-clusterextensions + apiGroup: rbac.authorization.k8s.io +--- +{{- end }} apiVersion: v1 kind: Pod metadata: @@ -102,12 +132,20 @@ spec: echo "Starting Test" - {{- if .Values.serverlessLogicOperator.enabled }} - kubectl get subscription {{ .Values.serverlessOperator.subscription.spec.name }} -n {{ .Values.serverlessOperator.subscription.namespace }} || exit 1 + {{- if .Values.serverlessOperator.enabled }} + {{- if eq (include "olm-version" .) "v1" }} + kubectl get clusterextension {{ .Values.serverlessOperator.subscription.spec.name }} || exit 1 + {{- else }} + kubectl get subscription.operators.coreos.com {{ .Values.serverlessOperator.subscription.spec.name }} -n {{ .Values.serverlessOperator.subscription.namespace }} || exit 1 + {{- end }} {{- end }} {{- if .Values.serverlessLogicOperator.enabled }} - kubectl get subscription {{ .Values.serverlessLogicOperator.subscription.name }} -n {{ .Values.serverlessLogicOperator.subscription.namespace }} || exit 1 + {{- if eq (include "olm-version" .) "v1" }} + kubectl get clusterextension {{ .Values.serverlessLogicOperator.subscription.spec.name }} || exit 1 + {{- else }} + kubectl get subscription.operators.coreos.com {{ .Values.serverlessLogicOperator.subscription.spec.name }} -n {{ .Values.serverlessLogicOperator.subscription.namespace }} || exit 1 + {{- end }} {{- end }} echo "Test passed!" diff --git a/charts/orchestrator-infra/values.schema.json b/charts/orchestrator-infra/values.schema.json index 1dba81cbf..6c9c613eb 100644 --- a/charts/orchestrator-infra/values.schema.json +++ b/charts/orchestrator-infra/values.schema.json @@ -1,9 +1,96 @@ { "$id": "https://raw.githubusercontent.com/redhat-developer/rhdh-chart/main/charts/orchestrator-infra/values.schema.json", "properties": { + "olm": { + "additionalProperties": false, + "properties": { + "catalog": { + "additionalProperties": false, + "properties": { + "selector": { + "additionalProperties": false, + "properties": { + "matchExpressions": { + "items": { + "additionalProperties": false, + "properties": { + "key": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "values": { + "items": { + "type": "string" + }, + "type": "array" + } + }, + "required": [ + "key", + "operator" + ], + "type": "object" + }, + "type": "array" + }, + "matchLabels": { + "additionalProperties": { + "type": "string" + }, + "properties": { + "olm.operatorframework.io/metadata.name": { + "default": "openshift-redhat-operators", + "title": "ClusterCatalog selector for OLM v1 ClusterExtension resources", + "type": "string" + } + }, + "type": "object" + } + }, + "type": "object" + } + }, + "type": "object" + } + }, + "type": "object" + }, + "olmVersion": { + "default": "v0", + "enum": [ + "v0", + "v1" + ], + "title": "OLM API version to use for operator installation", + "type": "string" + }, "serverlessLogicOperator": { "additionalProperties": false, "properties": { + "clusterExtension": { + "additionalProperties": false, + "properties": { + "serviceAccount": { + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-logic-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + }, + "type": "object" + } + }, + "type": "object" + }, + "createNamespace": { + "default": true, + "title": "Whether to create the operator namespace (set to false if namespace already exists)", + "type": "boolean" + }, "enabled": { "default": true, "title": "Whether the operator should be deployed by the chart", @@ -62,6 +149,28 @@ "serverlessOperator": { "additionalProperties": false, "properties": { + "clusterExtension": { + "additionalProperties": false, + "properties": { + "serviceAccount": { + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + }, + "type": "object" + } + }, + "type": "object" + }, + "createNamespace": { + "default": true, + "title": "Whether to create the operator namespace (set to false if namespace already exists)", + "type": "boolean" + }, "enabled": { "default": true, "title": "Whether the operator should be deployed by the chart", diff --git a/charts/orchestrator-infra/values.schema.tmpl.json b/charts/orchestrator-infra/values.schema.tmpl.json index 778e9eee0..4b2b44a14 100644 --- a/charts/orchestrator-infra/values.schema.tmpl.json +++ b/charts/orchestrator-infra/values.schema.tmpl.json @@ -4,6 +4,65 @@ "title": "Root Schema", "type": "object", "properties": { + "olmVersion": { + "default": "v0", + "enum": ["v0", "v1"], + "title": "OLM API version to use for operator installation", + "type": "string" + }, + "olm": { + "type": "object", + "additionalProperties": false, + "properties": { + "catalog": { + "type": "object", + "additionalProperties": false, + "properties": { + "selector": { + "type": "object", + "additionalProperties": false, + "properties": { + "matchLabels": { + "type": "object", + "additionalProperties": { + "type": "string" + }, + "properties": { + "olm.operatorframework.io/metadata.name": { + "default": "openshift-redhat-operators", + "title": "ClusterCatalog selector for OLM v1 ClusterExtension resources", + "type": "string" + } + } + }, + "matchExpressions": { + "type": "array", + "items": { + "type": "object", + "additionalProperties": false, + "properties": { + "key": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "values": { + "type": "array", + "items": { + "type": "string" + } + } + }, + "required": ["key", "operator"] + } + } + } + } + } + } + } + }, "serverlessLogicOperator": { "type": "object", "additionalProperties": false, @@ -13,6 +72,11 @@ "title": "Whether the operator should be deployed by the chart", "type": "boolean" }, + "createNamespace": { + "default": true, + "title": "Whether to create the operator namespace (set to false if namespace already exists)", + "type": "boolean" + }, "subscription": { "type": "object", "additionalProperties": false, @@ -59,6 +123,23 @@ } } } + }, + "clusterExtension": { + "type": "object", + "additionalProperties": false, + "properties": { + "serviceAccount": { + "type": "object", + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-logic-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + } + } + } } } }, @@ -71,6 +152,11 @@ "title": "Whether the operator should be deployed by the chart", "type": "boolean" }, + "createNamespace": { + "default": true, + "title": "Whether to create the operator namespace (set to false if namespace already exists)", + "type": "boolean" + }, "subscription": { "additionalProperties": false, "type": "object", @@ -112,6 +198,23 @@ } } } + }, + "clusterExtension": { + "type": "object", + "additionalProperties": false, + "properties": { + "serviceAccount": { + "type": "object", + "additionalProperties": false, + "properties": { + "name": { + "default": "serverless-operator-installer", + "title": "Service account used by OLM v1 to install the operator", + "type": "string" + } + } + } + } } } }, diff --git a/charts/orchestrator-infra/values.yaml b/charts/orchestrator-infra/values.yaml index cba801807..d186287c7 100644 --- a/charts/orchestrator-infra/values.yaml +++ b/charts/orchestrator-infra/values.yaml @@ -1,6 +1,17 @@ +# -- OLM API version to use for operator installation (`v0` or `v1`) +olmVersion: v0 +olm: + catalog: + # -- ClusterCatalog selector for OLM v1 ClusterExtension resources + selector: + matchLabels: + olm.operatorframework.io/metadata.name: openshift-redhat-operators + serverlessLogicOperator: # -- whether the operator should be deployed by the chart enabled: true + # -- whether to create the operator namespace (set to false if namespace already exists) + createNamespace: true subscription: # -- namespace where the operator should be deployed namespace: openshift-serverless-logic @@ -16,10 +27,16 @@ serverlessLogicOperator: sourceNamespace: openshift-marketplace # -- The initial version of the operator, must match CRDs installed by the chart startingCSV: logic-operator.v1.38.0 + clusterExtension: + serviceAccount: + # -- service account used by OLM v1 to install the operator + name: serverless-logic-operator-installer serverlessOperator: # -- whether the operator should be deployed by the chart enabled: true + # -- whether to create the operator namespace (set to false if namespace already exists) + createNamespace: true subscription: # -- namespace where the operator should be deployed namespace: openshift-serverless @@ -33,6 +50,10 @@ serverlessOperator: # -- name of the catalog source source: redhat-operators sourceNamespace: openshift-marketplace + clusterExtension: + serviceAccount: + # -- service account used by OLM v1 to install the operator + name: serverless-operator-installer tests: # -- Whether to create the test pod used for testing the Release using `helm test`.