Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump dependencies #1202

Merged
merged 29 commits into from
Sep 18, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
e6ede2a
Upgrade github_com_gardener_gardener-extension-shoot-dns-service (#1074)
gardener-robot-ci-1 Apr 21, 2023
265707a
Upgrade github_com_gardener_gardener-extension-provider-aws (#1072)
gardener-robot-ci-3 Apr 21, 2023
a04f30f
Upgrade github_com_gardener_gardener-extension-provider-openstack (#1…
gardener-robot-ci-1 Apr 21, 2023
5042b2a
Upgrade github_com_gardener_gardener-extension-provider-azure (#1070)
gardener-robot-ci-1 Apr 21, 2023
32e2620
Upgrade github_com_gardener_gardener-extension-provider-gcp (#1069)
gardener-robot-ci-2 Apr 21, 2023
ff769ff
[ci:component:github.com/gardener/dashboard:1.67.0->1.68.2] (#1068)
gardener-robot-ci-3 Apr 21, 2023
aee3f60
Upgrade github_com_gardener_gardener-extension-provider-vsphere (#1065)
gardener-robot-ci-3 Apr 21, 2023
29c4b65
Upgrade github_com_gardener_gardener-extension-networking-calico (#1062)
gardener-robot-ci-2 Apr 21, 2023
b5b820b
Upgrade github_com_gardener_gardener-extension-shoot-cert-service (#1…
gardener-robot-ci-2 Apr 21, 2023
07789f6
adapt dashboard deployment to helm chart changes"
Diaphteiros Apr 21, 2023
df36937
upgrade Gardener to v1.67.2
Diaphteiros Apr 21, 2023
22c17d2
fix problems with Gardener network policies
Diaphteiros Aug 22, 2023
2386e4e
fix certificate SANs
Diaphteiros Aug 25, 2023
f891296
Upgrade github_com_gardener_gardener-extension-shoot-cert-service (#1…
gardener-robot-ci-1 Aug 25, 2023
c329803
Upgrade github_com_gardener_cert-management (#1186)
gardener-robot-ci-2 Aug 25, 2023
1286ca0
Upgrade github_com_gardener_gardener-extension-shoot-dns-service (#1185)
gardener-robot-ci-1 Aug 25, 2023
22136c5
Upgrade github_com_gardener_gardener-extension-provider-vsphere (#1184)
gardener-robot-ci-2 Aug 25, 2023
6e73728
Upgrade github_com_gardener_gardener-extension-runtime-gvisor (#1183)
gardener-robot-ci-1 Aug 25, 2023
720c31b
Upgrade github_com_gardener_gardener-extension-networking-calico (#1177)
gardener-robot-ci-1 Aug 25, 2023
cae26b5
Upgrade github_com_gardener_gardener-extension-provider-azure (#1176)
gardener-robot-ci-2 Aug 25, 2023
389cc3c
Upgrade github_com_gardener_gardener-extension-provider-openstack (#1…
gardener-robot-ci-1 Aug 25, 2023
4d9f4f1
Upgrade github_com_gardener_gardener-extension-provider-aws (#1170)
gardener-robot-ci-1 Aug 25, 2023
26bf20c
Upgrade github_com_gardener_gardener-extension-provider-gcp (#1168)
gardener-robot-ci-1 Aug 25, 2023
cdc202c
Upgrade github_com_gardener_external-dns-management (#1164)
gardener-robot-ci-3 Aug 25, 2023
02d3601
[ci:component:github.com/gardener/gardener-extension-os-ubuntu:v1.21.…
Diaphteiros Aug 28, 2023
cef2de1
[ci:component:github.com/gardener/gardener-extension-os-suse-chost:v1…
gardener-robot-ci-1 Aug 25, 2023
27d7d6e
[ci:component:github.com/gardener/gardener-extension-os-gardenlinux:v…
gardener-robot-ci-1 Aug 25, 2023
9d786ce
update k8s versions and machine images
Diaphteiros Aug 25, 2023
b4db5ee
fix certificate SANs issues
Diaphteiros Sep 18, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions acre.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -280,6 +280,18 @@ landscape:
<<: (( merge ))
type: (( .dns_type_mapping[iaas[0].type] ))
credentials: (( iaas[0].credentials ))
domains:
<<: (( merge none ))
wildcard_ingress_dns: (( "*." ingress_dns ))
ingress_dns: (( "ing." landscape.domain ))
issuer_url: (( .landscape.identity.issuerUrl || "https://" identity_dns "/oidc" ))
callback_url: (( dashboard_url "/auth/callback" ))
connector_callback_url: (( dashboard_url "/oidc/callback" ))
dashboard_url: (( "https://" dashboard_dns ))
identity_url: (( "https://" identity_dns ))
identity_dns: (( ( .landscape.identity.useIdentityDomain || false ) ? "identity." ingress_dns :dashboard_dns ))
dashboard_dns: (( "gardener." ingress_dns ))

dns_type_mapping:
<<: (( &temporary ))
gcp: google-clouddns
Expand Down
6 changes: 3 additions & 3 deletions components/cert-manager/cert/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ settings:
certificate:
name: dashboard-identity-ingress
domains:
- (( "*." imports.ingress-controller.export.ingress_domain ))
- (( .landscape.domains.wildcard_ingress_dns ))
- (( .landscape.dashboard.cname.domain || ~~ ))
secret_name: identity-dashboard-tls
namespace: (( landscape.namespace ))
Expand All @@ -26,8 +26,8 @@ cert:
annotations:
cert.gardener.cloud/class: (( imports.cert-controller.export.certClass ))
spec:
commonName: (( .settings.certificate.domains[0] ))
dnsNames: (( .settings.certificate.domains[1..] ))
commonName: (( .landscape.domains.identity_dns ))
dnsNames: (( .settings.certificate.domains ))
secretRef:
name: (( .settings.certificate.secret_name ))
namespace: (( .settings.certificate.namespace ))
Expand Down
89 changes: 46 additions & 43 deletions components/dashboard/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -45,48 +45,51 @@ dashboard:
deploy: (( "--kube-version=" .imports.k8sversion.export.k8sVersions.base ))
values:
global:
apiServerUrl: (( imports.kube_apiserver.export.apiserver_url ))
apiServerCa: (( imports.kube_apiserver.export.kube_apiserver_ca.cert ))
sessionSecret: (( rand("[:alnum:]", 30) ))
ingress:
tls:
secretName: (( imports.cert.export.certificate.secret_name ))
hosts:
- (( imports.identity.export.dashboard_dns ))
- (( .landscape.dashboard.cname.domain || ~~ ))
annotations:
<<: (( .landscape.dashboard.ingress.annotations || ~~ ))
image:
repository: (( .dashboard_version.image_repo || ~~ ))
tag: (( .dashboard_version.image_tag || ~~ ))
pullPolicy: (( defined( tag ) -and tag != "latest" ? "IfNotPresent" :"Always" ))
oidc:
issuerUrl: (( imports.identity.export.issuer_url ))
ca: (( imports.cert-controller.export.ca.crt || ~~ ))
clientId: "dashboard"
clientSecret: (( imports.identity.export.dashboardClientSecret ))
public:
clientId: kube-kubectl
clientSecret: (( imports.identity.export.kubectlClientSecret ))
kubeconfig: (( format( "((!!! asyaml( merge( read( \"%s/export/kube-apiserver/kubeconfig_internal_merge_snippet\", \"yaml\" ), read( \"%s/kubectl_sa/sa_%s.kubeconfig\" , \"yaml\") ) ) ))", env.ROOTDIR, env.GENDIR, .settings.serviceaccount_name ) ))
podLabels:
<<: (( ( .landscape.gardener.network-policies.active || false ) ? ~ :~~ ))
networking.gardener.cloud/to-dns: allowed
networking.gardener.cloud/to-garden-kube-apiserver: allowed
networking.gardener.cloud/to-identity: allowed
networking.gardener.cloud/to-ingress: allowed
networking.gardener.cloud/to-world: allowed
networking.gardener.cloud/to-inside: allowed
gitHub: (( .landscape.dashboard.gitHub || ~~ ))
frontendConfig:
<<: (( .landscape.dashboard.frontendConfig || ~ ))
seedCandidateDeterminationStrategy: (( .imports.gardener_virtual.export.gardener.seedCandidateDeterminationStrategy ))
features:
<<: (( .landscape.dashboard.frontendConfig.features || ~ ))
terminalEnabled: (( ( .landscape.dashboard.terminals.active || false ) ))
dashboard:
apiServerUrl: (( imports.kube_apiserver.export.apiserver_url ))
apiServerCa: (( imports.kube_apiserver.export.kube_apiserver_ca.cert ))
sessionSecret: (( rand("[:alnum:]", 30) ))
ingress:
tls:
secretName: (( imports.cert.export.certificate.secret_name ))
hosts:
- (( .landscape.domains.dashboard_dns ))
- (( .landscape.dashboard.cname.domain || ~~ ))
annotations:
<<: (( .landscape.dashboard.ingress.annotations || ~~ ))
image:
repository: (( .dashboard_version.image_repo || ~~ ))
tag: (( .dashboard_version.image_tag || ~~ ))
pullPolicy: (( defined( tag ) -and tag != "latest" ? "IfNotPresent" :"Always" ))
oidc:
issuerUrl: (( .landscape.domains.issuer_url ))
ca: (( imports.cert-controller.export.ca.crt || ~~ ))
clientId: "dashboard"
clientSecret: (( imports.identity.export.dashboardClientSecret ))
public:
clientId: kube-kubectl
clientSecret: (( imports.identity.export.kubectlClientSecret ))
kubeconfig: (( format( "((!!! asyaml( merge( read( \"%s/export/kube-apiserver/kubeconfig_internal_merge_snippet\", \"yaml\" ), read( \"%s/kubectl_sa/sa_%s.kubeconfig\" , \"yaml\") ) ) ))", env.ROOTDIR, env.GENDIR, .settings.serviceaccount_name ) ))
podLabels:
<<: (( ( .landscape.gardener.network-policies.active || false ) ? ~ :~~ ))
networking.gardener.cloud/to-dns: allowed
networking.gardener.cloud/to-garden-kube-apiserver: allowed
networking.gardener.cloud/to-identity: allowed
networking.gardener.cloud/to-ingress: allowed
networking.gardener.cloud/to-world: allowed
networking.gardener.cloud/to-inside: allowed
gitHub: (( .landscape.dashboard.gitHub || ~~ ))
frontendConfig:
<<: (( .landscape.dashboard.frontendConfig || ~ ))
seedCandidateDeterminationStrategy: (( .imports.gardener_virtual.export.gardener.seedCandidateDeterminationStrategy ))
features:
<<: (( .landscape.dashboard.frontendConfig.features || ~ ))
terminalEnabled: (( ( .landscape.dashboard.terminals.active || false ) ))
resources:
<<: (( .landscape.dashboard.resources || ~~ ))
terminal: (( ( .landscape.dashboard.terminals.active || false ) ? *.terminal_config :~~ ))
resources:
<<: (( .landscape.dashboard.resources || ~~ ))
virtualGarden:
enabled: true

terminal_config:
<<: (( &temporary &template ))
Expand Down Expand Up @@ -129,7 +132,7 @@ cname_dnsentry:
spec:
dnsName: (( .landscape.dashboard.cname.domain || ~~ ))
targets:
- (( .imports.identity.export.dashboard_dns ))
- (( .landscape.domains.dashboard_dns ))
ttl: 120

util:
Expand All @@ -138,7 +141,7 @@ util:

settings:
serviceaccount_name: gardener-dashboard
dashboard_url: (( .imports.identity.export.dashboard_url ))
dashboard_url: (( .landscape.domains.dashboard_url ))

kubectl_sa:
kubeconfig: (( .imports.kube_apiserver.export.kubeconfig ))
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,10 @@ spec:
labels:
app: {{ .Values.name }}
component: etcd
networking.gardener.cloud/to-world: allowed
networking.gardener.cloud/to-inside: allowed
networking.gardener.cloud/to-gardener-apiserver: allowed
networking.gardener.cloud/to-dns: allowed
spec:
containers:
- name: etcd
Expand Down
56 changes: 20 additions & 36 deletions components/gardencontent/profiles/manifests/manifest.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -33,17 +33,17 @@ defaults:
- <<: (( defaults.providerspec.machineImages || ~ ))
- name: gardenlinux
versions:
- version: 576.12.0
- version: 934.9.0
classification: supported
kubeletVersionConstraint: < 1.26
architectures:
- amd64
- amd64
- arm64
cri:
- name: docker
- containerRuntimes:
- type: gvisor
name: containerd
- version: 576.11.0
- name: docker
- containerRuntimes:
- type: gvisor
name: containerd
- version: 576.12.0
classification: deprecated
kubeletVersionConstraint: < 1.26
architectures:
Expand All @@ -53,29 +53,19 @@ defaults:
- containerRuntimes:
- type: gvisor
name: containerd
- name: ubuntu
versions:
- version: 18.4.20210415
classification: deprecated
architectures:
- amd64
cri:
- name: docker
- containerRuntimes:
- type: gvisor
name: containerd
- name: suse-chost
versions:
- version: 15.4.20221215
- version: 15.4.20230410
classification: supported
architectures:
- amd64
- amd64
- arm64
cri:
- name: docker
- containerRuntimes:
- type: gvisor
name: containerd
- version: 15.3.20220411
- name: docker
- containerRuntimes:
- type: gvisor
name: containerd
- version: 15.4.20221215
classification: deprecated
architectures:
- amd64
Expand All @@ -94,17 +84,11 @@ defaults:
kubernetes:
versions:
- classification: supported
version: 1.25.5
version: 1.26.6
- classification: supported
version: 1.24.9
version: 1.25.11
- classification: supported
version: 1.23.15
- classification: deprecated
version: 1.22.17
- classification: deprecated
version: 1.21.14
- classification: deprecated
version: 1.21.10
version: 1.24.15
- classification: deprecated
version: 1.20.15
version: 1.23.17
providerspec: (( *values.providerspec ))
Loading