From 097d3c37cbb42989fcf4d0c164c0551051ce4217 Mon Sep 17 00:00:00 2001 From: Liam Date: Sun, 22 Sep 2024 05:55:28 +0100 Subject: [PATCH] it's kinda meh --- infrastructure/kube-sphere/config.yaml | 206 ------------ infrastructure/kube-sphere/ingress.yaml | 21 -- infrastructure/kube-sphere/installer.yaml | 308 ------------------ infrastructure/kube-sphere/kustomization.yaml | 9 - infrastructure/kube-sphere/namespace.yaml | 13 - infrastructure/kustomization.yaml | 3 +- 6 files changed, 1 insertion(+), 559 deletions(-) delete mode 100644 infrastructure/kube-sphere/config.yaml delete mode 100644 infrastructure/kube-sphere/ingress.yaml delete mode 100644 infrastructure/kube-sphere/installer.yaml delete mode 100644 infrastructure/kube-sphere/kustomization.yaml delete mode 100644 infrastructure/kube-sphere/namespace.yaml diff --git a/infrastructure/kube-sphere/config.yaml b/infrastructure/kube-sphere/config.yaml deleted file mode 100644 index 5bc0fb0..0000000 --- a/infrastructure/kube-sphere/config.yaml +++ /dev/null @@ -1,206 +0,0 @@ ---- -apiVersion: installer.kubesphere.io/v1alpha1 -kind: ClusterConfiguration -metadata: - name: ks-installer - namespace: kubesphere-system - labels: - version: v3.4.0 -spec: - persistence: - storageClass: "nfs-csi" # If there is no default StorageClass in your cluster, you need to specify an existing StorageClass here. - authentication: - # adminPassword: "" # Custom password of the admin user. If the parameter exists but the value is empty, a random password is generated. If the parameter does not exist, P@88w0rd is used. - jwtSecret: "" # Keep the jwtSecret consistent with the Host Cluster. Retrieve the jwtSecret by executing "kubectl -n kubesphere-system get cm kubesphere-config -o yaml | grep -v "apiVersion" | grep jwtSecret" on the Host Cluster. - local_registry: "" # Add your private registry address if it is needed. - # dev_tag: "" # Add your kubesphere image tag you want to install, by default it's same as ks-installer release version. - etcd: - monitoring: false # Enable or disable etcd monitoring dashboard installation. You have to create a Secret for etcd before you enable it. - endpointIps: localhost # etcd cluster EndpointIps. It can be a bunch of IPs here. - port: 2379 # etcd port. - tlsEnable: true - common: - core: - console: - enableMultiLogin: true # Enable or disable simultaneous logins. It allows different users to log in with the same account at the same time. - port: 30880 - type: NodePort - - # apiserver: # Enlarge the apiserver and controller manager's resource requests and limits for the large cluster - # resources: {} - # controllerManager: - # resources: {} - redis: - enabled: false - enableHA: false - volumeSize: 2Gi # Redis PVC size. - openldap: - enabled: false - volumeSize: 2Gi # openldap PVC size. - minio: - volumeSize: 20Gi # Minio PVC size. - monitoring: - # type: external # Whether to specify the external prometheus stack, and need to modify the endpoint at the next line. - endpoint: http://prometheus-operated.kubesphere-monitoring-system.svc:9090 # Prometheus endpoint to get metrics data. - GPUMonitoring: # Enable or disable the GPU-related metrics. If you enable this switch but have no GPU resources, Kubesphere will set it to zero. - enabled: false - gpu: # Install GPUKinds. The default GPU kind is nvidia.com/gpu. Other GPU kinds can be added here according to your needs. - kinds: - - resourceName: "nvidia.com/gpu" - resourceType: "GPU" - default: true - es: # Storage backend for logging, events and auditing. - # master: - # volumeSize: 4Gi # The volume size of Elasticsearch master nodes. - # replicas: 1 # The total number of master nodes. Even numbers are not allowed. - # resources: {} - # data: - # volumeSize: 20Gi # The volume size of Elasticsearch data nodes. - # replicas: 1 # The total number of data nodes. - # resources: {} - enabled: false - logMaxAge: 7 # Log retention time in built-in Elasticsearch. It is 7 days by default. - elkPrefix: logstash # The string making up index names. The index name will be formatted as ks--log. - basicAuth: - enabled: false - username: "" - password: "" - externalElasticsearchHost: "" - externalElasticsearchPort: "" - opensearch: # Storage backend for logging, events and auditing. - # master: - # volumeSize: 4Gi # The volume size of Opensearch master nodes. - # replicas: 1 # The total number of master nodes. Even numbers are not allowed. - # resources: {} - # data: - # volumeSize: 20Gi # The volume size of Opensearch data nodes. - # replicas: 1 # The total number of data nodes. - # resources: {} - enabled: true - logMaxAge: 7 # Log retention time in built-in Opensearch. It is 7 days by default. - opensearchPrefix: whizard # The string making up index names. The index name will be formatted as ks--logging. - basicAuth: - enabled: true - username: "admin" - password: "admin" - externalOpensearchHost: "" - externalOpensearchPort: "" - dashboard: - enabled: false - alerting: # (CPU: 0.1 Core, Memory: 100 MiB) It enables users to customize alerting policies to send messages to receivers in time with different time intervals and alerting levels to choose from. - enabled: false # Enable or disable the KubeSphere Alerting System. - # thanosruler: - # replicas: 1 - # resources: {} - auditing: # Provide a security-relevant chronological set of records,recording the sequence of activities happening on the platform, initiated by different tenants. - enabled: false # Enable or disable the KubeSphere Auditing Log System. - # operator: - # resources: {} - # webhook: - # resources: {} - devops: # (CPU: 0.47 Core, Memory: 8.6 G) Provide an out-of-the-box CI/CD system based on Jenkins, and automated workflow tools including Source-to-Image & Binary-to-Image. - enabled: false # Enable or disable the KubeSphere DevOps System. - jenkinsCpuReq: 0.5 - jenkinsCpuLim: 1 - jenkinsMemoryReq: 4Gi - jenkinsMemoryLim: 4Gi # Recommend keep same as requests.memory. - jenkinsVolumeSize: 16Gi - events: # Provide a graphical web console for Kubernetes Events exporting, filtering and alerting in multi-tenant Kubernetes clusters. - enabled: false # Enable or disable the KubeSphere Events System. - # operator: - # resources: {} - # exporter: - # resources: {} - ruler: - enabled: true - replicas: 2 - # resources: {} - logging: # (CPU: 57 m, Memory: 2.76 G) Flexible logging functions are provided for log query, collection and management in a unified console. Additional log collectors can be added, such as Elasticsearch, Kafka and Fluentd. - enabled: false # Enable or disable the KubeSphere Logging System. - logsidecar: - enabled: true - replicas: 2 - # resources: {} - metrics_server: # (CPU: 56 m, Memory: 44.35 MiB) It enables HPA (Horizontal Pod Autoscaler). - enabled: false # Enable or disable metrics-server. - monitoring: - storageClass: "" # If there is an independent StorageClass you need for Prometheus, you can specify it here. The default StorageClass is used by default. - node_exporter: - port: 9100 - # resources: {} - # kube_rbac_proxy: - # resources: {} - # kube_state_metrics: - # resources: {} - # prometheus: - # replicas: 1 # Prometheus replicas are responsible for monitoring different segments of data source and providing high availability. - # volumeSize: 20Gi # Prometheus PVC size. - # resources: {} - # operator: - # resources: {} - # alertmanager: - # replicas: 1 # AlertManager Replicas. - # resources: {} - # notification_manager: - # resources: {} - # operator: - # resources: {} - # proxy: - # resources: {} - gpu: # GPU monitoring-related plug-in installation. - nvidia_dcgm_exporter: # Ensure that gpu resources on your hosts can be used normally, otherwise this plug-in will not work properly. - enabled: false # Check whether the labels on the GPU hosts contain "nvidia.com/gpu.present=true" to ensure that the DCGM pod is scheduled to these nodes. - # resources: {} - multicluster: - clusterRole: none # host | member | none # You can install a solo cluster, or specify it as the Host or Member Cluster. - network: - networkpolicy: # Network policies allow network isolation within the same cluster, which means firewalls can be set up between certain instances (Pods). - # Make sure that the CNI network plugin used by the cluster supports NetworkPolicy. There are a number of CNI network plugins that support NetworkPolicy, including Calico, Cilium, Kube-router, Romana and Weave Net. - enabled: false # Enable or disable network policies. - ippool: # Use Pod IP Pools to manage the Pod network address space. Pods to be created can be assigned IP addresses from a Pod IP Pool. - type: none # Specify "calico" for this field if Calico is used as your CNI plugin. "none" means that Pod IP Pools are disabled. - topology: # Use Service Topology to view Service-to-Service communication based on Weave Scope. - type: none # Specify "weave-scope" for this field to enable Service Topology. "none" means that Service Topology is disabled. - openpitrix: # An App Store that is accessible to all platform tenants. You can use it to manage apps across their entire lifecycle. - store: - enabled: false # Enable or disable the KubeSphere App Store. - servicemesh: # (0.3 Core, 300 MiB) Provide fine-grained traffic management, observability and tracing, and visualized traffic topology. - enabled: false # Base component (pilot). Enable or disable KubeSphere Service Mesh (Istio-based). - istio: # Customizing the istio installation configuration, refer to https://istio.io/latest/docs/setup/additional-setup/customize-installation/ - components: - ingressGateways: - - name: istio-ingressgateway - enabled: false - cni: - enabled: false - edgeruntime: # Add edge nodes to your cluster and deploy workloads on edge nodes. - enabled: false - kubeedge: # kubeedge configurations - enabled: false - cloudCore: - cloudHub: - advertiseAddress: # At least a public IP address or an IP address which can be accessed by edge nodes must be provided. - - "" # Note that once KubeEdge is enabled, CloudCore will malfunction if the address is not provided. - service: - cloudhubNodePort: "30000" - cloudhubQuicNodePort: "30001" - cloudhubHttpsNodePort: "30002" - cloudstreamNodePort: "30003" - tunnelNodePort: "30004" - # resources: {} - # hostNetWork: false - iptables-manager: - enabled: true - mode: "external" - # resources: {} - # edgeService: - # resources: {} - gatekeeper: # Provide admission policy and rule management, A validating (mutating TBA) webhook that enforces CRD-based policies executed by Open Policy Agent. - enabled: false # Enable or disable Gatekeeper. - # controller_manager: - # resources: {} - # audit: - # resources: {} - terminal: - # image: 'alpine:3.15' # There must be an nsenter program in the image - timeout: 600 # Container timeout, if set to 0, no timeout will be used. The unit is seconds diff --git a/infrastructure/kube-sphere/ingress.yaml b/infrastructure/kube-sphere/ingress.yaml deleted file mode 100644 index 5c05894..0000000 --- a/infrastructure/kube-sphere/ingress.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: traefik.io/v1alpha1 -kind: IngressRoute -metadata: - name: kubesphere-external-ingress - namespace: kube-system - annotations: - kubernetes.io/ingress.class: traefik-external -spec: - entryPoints: - - websecure - routes: - - match: Host(`kubesphere.local.fascinated.cc`) - kind: Rule - middlewares: - - name: default-headers - namespace: traefik - services: - - name: ks-console - port: 80 - tls: - secretName: fascinated-cc diff --git a/infrastructure/kube-sphere/installer.yaml b/infrastructure/kube-sphere/installer.yaml deleted file mode 100644 index 564656a..0000000 --- a/infrastructure/kube-sphere/installer.yaml +++ /dev/null @@ -1,308 +0,0 @@ ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - name: clusterconfigurations.installer.kubesphere.io -spec: - group: installer.kubesphere.io - versions: - - name: v1alpha1 - served: true - storage: true - schema: - openAPIV3Schema: - type: object - properties: - spec: - type: object - x-kubernetes-preserve-unknown-fields: true - status: - type: object - x-kubernetes-preserve-unknown-fields: true - scope: Namespaced - names: - plural: clusterconfigurations - singular: clusterconfiguration - kind: ClusterConfiguration - shortNames: - - cc - ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - name: ks-installer - namespace: kubesphere-system - ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - name: ks-installer -rules: - - apiGroups: - - "" - resources: - - "*" - verbs: - - "*" - - apiGroups: - - apps - resources: - - "*" - verbs: - - "*" - - apiGroups: - - extensions - resources: - - "*" - verbs: - - "*" - - apiGroups: - - batch - resources: - - "*" - verbs: - - "*" - - apiGroups: - - rbac.authorization.k8s.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - apiregistration.k8s.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - apiextensions.k8s.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - tenant.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - certificates.k8s.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - devops.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - monitoring.coreos.com - resources: - - "*" - verbs: - - "*" - - apiGroups: - - logging.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - jaegertracing.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - storage.k8s.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - admissionregistration.k8s.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - policy - resources: - - "*" - verbs: - - "*" - - apiGroups: - - autoscaling - resources: - - "*" - verbs: - - "*" - - apiGroups: - - networking.istio.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - config.istio.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - iam.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - notification.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - auditing.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - events.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - core.kubefed.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - installer.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - storage.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - security.istio.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - monitoring.kiali.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - kiali.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - networking.k8s.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - edgeruntime.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - types.kubefed.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - monitoring.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - application.kubesphere.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - alerting.kubesphere.io - resources: - - "*" - verbs: - - "*" - ---- -kind: ClusterRoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: ks-installer -subjects: - - kind: ServiceAccount - name: ks-installer - namespace: kubesphere-system -roleRef: - kind: ClusterRole - name: ks-installer - apiGroup: rbac.authorization.k8s.io - ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: ks-installer - namespace: kubesphere-system - labels: - app: ks-installer -spec: - replicas: 1 - selector: - matchLabels: - app: ks-installer - template: - metadata: - labels: - app: ks-installer - spec: - serviceAccountName: ks-installer - containers: - - name: installer - image: kubesphere/ks-installer:v3.4.0 - imagePullPolicy: "Always" - securityContext: - privileged: true - resources: - limits: - cpu: "1" - memory: 1Gi - requests: - cpu: 20m - memory: 100Mi - volumeMounts: - - mountPath: /etc/localtime - name: host-time - readOnly: true - volumes: - - hostPath: - path: /etc/localtime - type: "" - name: host-time diff --git a/infrastructure/kube-sphere/kustomization.yaml b/infrastructure/kube-sphere/kustomization.yaml deleted file mode 100644 index 922996c..0000000 --- a/infrastructure/kube-sphere/kustomization.yaml +++ /dev/null @@ -1,9 +0,0 @@ ---- -apiVersion: kustomize.config.k8s.io/v1beta1 -kind: Kustomization -namespace: kubesphere-system -resources: - - namespace.yaml - - config.yaml - - installer.yaml - - ingress.yaml diff --git a/infrastructure/kube-sphere/namespace.yaml b/infrastructure/kube-sphere/namespace.yaml deleted file mode 100644 index 6c5bcac..0000000 --- a/infrastructure/kube-sphere/namespace.yaml +++ /dev/null @@ -1,13 +0,0 @@ ---- -apiVersion: v1 -kind: Namespace -metadata: - name: kubesphere-system - labels: - pod-security.kubernetes.io/audit: privileged - pod-security.kubernetes.io/warn: privileged - pod-security.kubernetes.io/enforce: privileged - annotations: - pod-security.kubernetes.io/enforce: privileged - pod-security.kubernetes.io/audit: privileged - pod-security.kubernetes.io/warn: privileged diff --git a/infrastructure/kustomization.yaml b/infrastructure/kustomization.yaml index 947eccf..2e154dc 100644 --- a/infrastructure/kustomization.yaml +++ b/infrastructure/kustomization.yaml @@ -7,6 +7,5 @@ resources: - metallb - nfs - traefik - - kube-sphere - #- monitoring + - monitoring - alerting/flux