1633 Commits

Author SHA1 Message Date
Zuul
e1fa86947e Merge "Ingress: Add pod/container security context" 2019-04-24 18:00:05 +00:00
Zuul
18386af32f Merge "Update image links for Ceph." 2019-04-24 17:36:43 +00:00
Zuul
53235b6440 Merge "Rabbitmq: Fix security context" 2019-04-24 16:43:07 +00:00
Meg Heisler
a600471cb0 Define test specific timeouts for Armada LMA components
This adds test specific timeout to all LMA components in
Armada. This also removes test enabled true because
Armada enables tests by default

Change-Id: I893342b36ba27cbe7d3ce8767f73795e84a11732
2019-04-24 11:07:18 -05:00
Dmitrii Kabanov
b7c07a595c Update image links for Ceph.
Updated the links according to the decision here [1].
The convention for images is <imagename>:<tagging>
where <tagging> takes the format <version>-<distro>.

[1]: http://eavesdrop.openstack.org/irclogs/%23openstack-helm/%23openstack-helm.2019-03-07.log.html#t2019-03-07T17:50:58

Change-Id: I84f8ce731e428f8ef035c008ff615e712c78a1f4
2019-04-24 14:53:42 +00:00
Zuul
53e1278bab Merge "Fix prometheus metrics gathering in postrun job" 2019-04-24 14:26:09 +00:00
Rahul Khiyani
7f20bcd938 Rabbitmq: Fix security context
This PS fixes the use of the security context macros for the
rabbitmq chart

Change-Id: I91499757bd7af95132d0aee33a16d642e26439bb
2019-04-24 13:51:42 +00:00
RAHUL KHIYANI
b1900bbfc2 Ceph-provisioners: Fix security context
This PS fixes the use of the security context macros for the
ceph-provisioners chart

Change-Id: Iddeb643139f2e7798282e67e319f38d3a22cd10d
2019-04-24 04:57:23 +00:00
RAHUL KHIYANI
a5e8953bd4 ceph-mon: Fix security context
This PS fixes the use of the security context macros for the
ceph-mon chart.

Change-Id: Ibde448481c44f2753ddfe57e590ea7d05671793a
2019-04-23 23:18:21 -05:00
RAHUL KHIYANI
5be16a66d7 Elasticsearch: Fix security context
This PS fixes the use of the security context macros for the
elasticsearch chart.

Change-Id: I85a37aa4dec88222107323f17d10e5ff29f41648
2019-04-23 23:04:18 -05:00
RAHUL KHIYANI
befb8b65e8 Ingress: Add pod/container security context
This PS fixes the use of the security context macros for the
ingress chart.

Change-Id: I28171d529a27c3f203b02c031a6cf289fcc5f3e6
2019-04-24 03:12:16 +00:00
Meg Heisler
010faee9d5 Add wait.resource for LMA services to armada manifest
This adds the wait.resource.type to each LMA service in
the armada manifest

Change-Id: I86adbb1a5325ce2beef8506a406865e8db53876b
2019-04-24 00:39:05 +00:00
Zuul
0d009ce0ff Merge "Fluent-logging: Fix security context" 2019-04-23 23:12:18 +00:00
Zuul
ff7049f170 Merge "Memcached: Fix security context" 2019-04-23 21:15:25 +00:00
Steve Wilkerson
880f32f059 Fix Ceph deployment in apparmor job
This fixes the ceph deployment in the apparmor job as the previous
overrides weren't entirely correct.  This also reorders the
deployment steps in the apparmor job to enforce the sequential
naming scheme used

Change-Id: I161bae649d4ff67307abeadc12b3c7d321af31c7
2019-04-23 10:25:54 -05:00
Steve Wilkerson
2c11798c65 Update airship-divingbell check job
This updates the airship-divingbell repository defined in the
single node check job to use the correct repository namespace.

This also updates the divingbell check job to use the standard
osh-infra-gate-runner playbook as well as the minikube based
kubernetes deployment

Change-Id: Iff53279b3e09058deb323d092955cbf87230b5e5
2019-04-23 10:09:27 -05:00
RAHUL KHIYANI
e3bd69c084 Fluent-logging: Fix security context
This PS fixes the use of the security context macros for the
fluent-logging chart.

Change-Id: I2cd12015732bddb642136ba14f88ed2c248d519d
2019-04-23 14:40:14 +00:00
Zuul
84c12d57e7 Merge "prometheus: Fix security context" 2019-04-23 14:35:47 +00:00
Zuul
f29fd53acb Merge "prometheus-alertmanager: Fix security context" 2019-04-23 14:35:45 +00:00
Zuul
0c1a144c1b Merge "prometheus-kube-state-metrics: Fix security context" 2019-04-23 14:35:44 +00:00
Zuul
a9af19a7da Merge "prometheus-node-exporter: Fix security context" 2019-04-23 14:35:43 +00:00
RAHUL KHIYANI
2cc0317fc3 Memcached: Fix security context
This PS adds the missing allowPrivilegeEscalation flag in container
securityContext

Change-Id: Ie10951bd43de563fec09795feedc0050dcd4ebbe
2019-04-23 13:29:44 +00:00
Zuul
d7830c55c6 Merge "Nagios: Fix security context" 2019-04-23 13:05:28 +00:00
RAHUL KHIYANI
cd99469454 Kibana: Fix security context
This PS fixes the use of the security context macros for the
Kibana chart.

Change-Id: Iaad821ac3df7e42eb52ba2f274fe47e4847d30af
2019-04-23 04:32:41 +00:00
RAHUL KHIYANI
e1c9a35230 Grafana: Add security context to chart and read-only-fs
This PS adds the security context macros to the grafana chart,
and moves the default to read-only-rootfs for all containers

Change-Id: Ie79e3bfc6af07b16cd53eddae17eceac3d9f8613
2019-04-23 03:22:21 +00:00
Zuul
c5eee25fbd Merge "prometheus-openstack-exporter: Fix security context" 2019-04-23 02:12:58 +00:00
Zuul
a0360d07ea Merge "Mariadb: Display error if user is not create" 2019-04-23 02:02:14 +00:00
RAHUL KHIYANI
916bdabee7 prometheus: Fix security context
This PS fixes the use of the security context macros for the
prometheus chart.

Change-Id: I0abb309132a9954a140cbf76463724c5e2c7c5f3
2019-04-23 00:00:36 +00:00
RAHUL KHIYANI
95bb125207 prometheus-alertmanager: Fix security context
This PS fixes the pod application name and also adds security context
to initcontainer

Change-Id: Ia7cd5057247b0a07f88406259d41601659688f1a
2019-04-22 15:59:36 -05:00
RAHUL KHIYANI
2cdcaa84b5 prometheus-openstack-exporter: Fix security context
This PS fixes the use of the security context macros for the
openstack-exporter chart.

Change-Id: I91e9f6810442477c167a07e2d8ffa4f01beb66d3
2019-04-22 18:35:32 +00:00
Zuul
5aa3d47398 Merge "ceph-rgw: Add pod/container security context" 2019-04-22 18:19:53 +00:00
Gupta, Sangeet (sg774j)
003f765e91 Mariadb: Display error if user is not create
This PS updates the create-mysql-user.sh to display the error
if the exporter user was not created successfully.

Change-Id: I03505b5fb569cda199c2803086b77206b810ea3f
2019-04-22 18:07:28 +00:00
Zuul
2f747ad6ba Merge "Libvirt: Fix security context" 2019-04-22 16:17:39 +00:00
rk0850
9ea6575ed9 ceph-rgw: Add pod/container security context
This updates the ceph-rgw  chart to include the pod
security context on the pod template

This also adds the container security context

Change-Id: Ic75a1decfe156e1e8aa2ebe38238f6b77abb71f8
2019-04-22 15:33:23 +00:00
RAHUL KHIYANI
0ae22f4c1c prometheus-kube-state-metrics: Fix security context
This PS fixes the application name to holistic manner

Change-Id: Ib68c6fc114962fd53a5fcd2ce9e79bfefd5d94a3
2019-04-22 10:29:33 -05:00
RAHUL KHIYANI
bc9bbe4e34 prometheus-node-exporter: Fix security context
This PS fixes the use of the security context macros for the
node-exporter chart.

Change-Id: I7009a5675096036ac9f214d70c853830b7132264
2019-04-22 10:17:38 -05:00
RAHUL KHIYANI
77f20875b5 Libvirt: Fix security context
This PS fixes the use of the security context macros for the
libvirt chart.

Change-Id: I3340742a0eaf9cffa9263642fd2b987363128ed5
2019-04-22 13:45:50 +00:00
Pete Birley
a6558281a1 Gate: Remove stable helm repo is present to improve build time
This PS remvoes the stable helm repo, if present, to improve the
build time of patches.

Change-Id: Id6ec86e5ff426994b12adf4ca8e80eda2e52f147
Signed-off-by: Pete Birley <pete@port.direct>
2019-04-22 07:27:12 -05:00
Steve Wilkerson
84c6931c98 Fix prometheus metrics gathering in postrun job
This adds '|| true' to the curl command for gathering metrics from
prometheus exporters in the postrun job. After the move to
minikube for single node jobs, the headless services for the
kubernetes components no longer work as intended. The addition of
'|| true' allows the post run job to continue through the list
of services tied to the prometheus exporters without the task
failing outright

Change-Id: I56f0f56b799c3df9b2bd66a2c2044d71473606e3
2019-04-22 12:02:11 +00:00
RAHUL KHIYANI
b8f5be0fce Nagios: Fix security context
This PS fixes the use of the security context macros for the
nagios chart.

Change-Id: Ibe7ca7b87153f4e5535b9c8b1bf1ba63edb5e3af
2019-04-22 01:16:29 -05:00
Zuul
274697f9cf Merge "Registry: Add pod/container security context" 2019-04-22 05:30:59 +00:00
Rahul Khiyani
8edaf9fa31 Registry: Add pod/container security context
This updates the registry chart to include the pod
security context on the pod template

This also adds the container security context

Change-Id: I36b6a2cf291dda2f991843c07ba116f3bf936d03
2019-04-21 17:52:21 -05:00
Zuul
8029fddf60 Merge "Ceph-Client: Add security context to chart and read-only-fs" 2019-04-21 20:47:49 +00:00
Zuul
291781e6de Merge "Ceph: Make /etc/ceph and /run emptydirs uniformly across all pods" 2019-04-21 20:32:59 +00:00
Zuul
e754a6dbd9 Merge "Calico: Fix security context" 2019-04-21 19:12:02 +00:00
Pete Birley
f569cf0d5c Ceph-Client: Add security context to chart and read-only-fs
This PS adds the security context macros to the ceph-client chart,
and moves the default to read-only-rootfs for all containers.

Change-Id: I2fe03f31cc59e1cda2bf0396ae6e3aca5c440a16
Signed-off-by: Pete Birley <pete@port.direct>
2019-04-21 19:06:24 +00:00
Pete Birley
dece008337 Ceph: Make /etc/ceph and /run emptydirs uniformly across all pods
This PS updates the ceph charts to make /etc/ceph an emptydir
uniformly across all charts, both ensuring no default config is loaded,
and also permitting read-only filesystems to back the containers.

Additionally /run is uniformly applied across all long running pods
as a memory backed emptydir.

Change-Id: I00d1b15758b7eb4476fb950ddcb38db9a5149ad0
Signed-off-by: Pete Birley <pete@port.direct>
2019-04-21 19:06:18 +00:00
Zuul
b4f9df436f Merge "OpenvSwitch: use security context macros" 2019-04-21 15:48:40 +00:00
Zuul
ac7543b4e9 Merge "OvS: Improve security options for ovs-db pod" 2019-04-21 15:48:39 +00:00
Pete Birley
eb58abb880 Calico: Fix security context
This PS fixes the use of the security context macros for the
calico chart.

Change-Id: I2ed8a5e994726b625d76a2c308895441c7d174a9
Signed-off-by: Pete Birley <pete@port.direct>
2019-04-21 15:46:16 +00:00