Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|
Repository files navigation
* Workshop Namespace Operator Kubernetes Operator for setting up Kubernetes Namespace and User privileged for workshop sessions. Repository also provides CRD APIs for golang in folder ~pkg/apis~. ** About Workshop Namespace Operator is created using [[https://github.com/operator-framework/operator-sdk/blob/master/doc/ansible/user-guide.md][operator-sdk framework]]. The operator will ensure that there is namespace for each WorkshopNamespace CR. For example this Custom Resource: #+begin_src yaml apiVersion: operator.prgcont.cz/v1alpha1 kind: WorkshopNamespace metadata: name: example-ns #+end_src will result in: - /Namespace/: ~example-ns~ - /ServiceAccount/: ~workshop-user~ - /RoleBinding/ granting ~workshop-user~ namespaced ~cluster-admin~ privileges - /Namespace/: ~default~ (or namespace where operator runs in) - /Secret/: ~kubeconfig-example-ns~ - Secret contains kubeconfig for created /ServiceAccount/ *** Configuration Operator is configured with /ConfigMap/ ~kubernetes-server~, it must contain key ~data.server~ which declares which Server will be set in all generated kubeconfigs. Example config: #+begin_src yaml apiVersion: v1 kind: ConfigMap metadata: name: kubernetes-server data: server: https://workshop.prgcont.cz:443 #+end_src ** Deploy to k8s cluster Publish container: #+begin_src bash operator-sdk build prgcont/workshop-namespace-operator:v0.0.2 docker push prgcont/workshop-namespace-operator:v0.0.2 #+end_src Create CRD in target cluster: #+begin_src bash export OPERATOR_NAMESPACE=default kubectl -n ${OPERATOR_NAMESPACE} create -f deploy/crds/workshopnamespaces_v1alpha1_operator_crd.yaml #+end_src Create Operator #+begin_src bash kubectl -n ${OPERATOR_NAMESPACE} create -f deploy/role.yaml,deploy/role_binding.yaml,deploy/clusterrole_binding.yaml,deploy/service_account.yaml # Update operator container image and deploy to cluster sed 's/{{ REPLACE_IMAGE }}/prgcont\/workshop-namespace-operator:v0.0.2/' deploy/operator.yaml | kubectl -n ${OPERATOR_NAMESPACE} create -f - sed 's/{{ KUBERNETES_SERVER }}/https:\/\/192.168.64.21:8443/' deploy/config.yaml | kubectl -n ${OPERATOR_NAMESPACE} create -f - #+end_src Create test CR to verify if namespace is created: #+begin_src bash kubectl -n ${OPERATOR_NAMESPACE} create -f deploy/crds/workshopnamespaces_v1alpha1_operator_cr.yaml #+end_src Verify that Namespace test-ns was created #+begin_src bash kubectl get ns # Objects in namespace kubectl -n test-ns get serviceaccount,rolebinding # NAME SECRETS AGE # sa/default 1 3d # sa/workshop-user 1 3d # NAME KIND SUBJECTS # rolebindings/test-nsadmin RoleBinding.v1.rbac.authorization.k8s.io 1 item(s) #+end_src *** Cleanup cluster #+begin_src bash kubectl -n ${OPERATOR_NAMESPACE} delete workshopnamespace $(kubectl get workshopnamespace -o jsonpath='{.items[*].metadata.name}') kubectl -n ${OPERATOR_NAMESPACE} delete -f deploy/role.yaml,deploy/role_binding.yaml,deploy/clusterrole_binding.yaml,deploy/service_account.yaml kubectl -n ${OPERATOR_NAMESPACE} delete deployment workshop-namespace-operator kubectl -n ${OPERATOR_NAMESPACE} delete configmap kubernetes-server kubectl delete -f deploy/crds/workshopnamespaces_v1alpha1_operator_crd.yaml #+end_src ** Local testing *** Prerequisites - git - docker version 17.03+. - kubectl version v1.9.0+. - ansible version v2.6.0+ - ansible-runner version v1.1.0+ - ansible-runner-http version v1.0.0+ - dep version v0.5.0+. (Optional if you aren't installing from source) - go version v1.10+. (Optional if you aren't installing from source) - Access to a Kubernetes v.1.9.0+ cluster. See [[fro more ][official prerequisites]] for more details. Register CRD: #+begin_src bash kubectl apply -f ./deploy/crds/workshopnamespaces_v1alpha1_operator_crd.yaml #+end_src *** Getting Started Start minikube cluster #+begin_src bash minikube start --kubernetes-version v1.12.4 #+end_src Create CRD in k8s API #+begin_src bash kubectl apply -f deploy/crds/workshopnamespaces_v1alpha1_operator_crd.yaml #+end_src Update /watches.yaml/ ~role~ section to reflect path on your computer, e.g. ~/home/<USERNAME>/workshop-namespace-operator/roles/workshopnamespace~. Start Operator locally: #+begin_src bash # Either start runner directly ansible-runner -vv --rotate-artifacts 1 --role workshopnamespace --roles-path ~/.go/src/github.com/prgcont/workshop-namespace-operator/roles/ --hosts localhost -i test run ./ # or using operator-sdk operator-sdk up local #+end_src Create test CR: #+begin_src bash kubectl apply -f ./deploy/crds/workshopnamespaces_v1alpha1_operator_cr.yaml #+end_src ** Develop Adding k8s go client CRD using kubebuilder (already done). #+begin_src bash kubebuilder init --domain prgcont.cz --license apache2 --owner "The Prgcont Team" kubebuilder create api --group operator --version v1alpha1 --kind WorkshopNamespace #+end_src Re-generate go client libraries for ~WorkshopNamespace~ CRD. #+begin_src bash vendor/k8s.io/code-generator/generate-groups.sh all \ github.com/prgcont/workshop-namespace-operator/pkg/client \ github.com/prgcont/workshop-namespace-operator/pkg/apis \ operator:v1alpha1 #+end_src It is necessary to re-generate client libraries every CRD is updated.