1072 Commits

Author SHA1 Message Date
Zuul
10c9651601 Merge "Basic support for BGP communities in calico" 2019-01-12 23:16:58 +00:00
Zuul
ded5de14fa Merge "Running agents on all nodes." 2019-01-11 04:15:27 +00:00
Michael Beaver
e34270c51e Basic support for BGP communities in calico
This creates a new section in calico/values.yaml that enables
BGP communities to be applied to a cidr by using the bird_ipam
templates.

Change-Id: I4dbbc8d8e761e0484eeb7c8bf0fefa28d29493e5
2019-01-10 14:02:16 -06:00
Sungil Im
b9e864a456 Running agents on all nodes.
Using a node selector can not run the prometheus-process-exporter
on the master node. So, This PS changes the scheduling to use
either taint/toleration or the node selector.

Change-Id: Ie84b2d2e0354fa927c1010c18392667dad171483
2019-01-10 05:46:53 -05:00
lijunjie
32b3ac3723 Fix the misspelling of "argument"
Change-Id: If78a27fe0d28a60d3dbbe0ee21d8209b2cfd633c
2019-01-10 16:41:17 +08:00
Zuul
730e7811c2 Merge "Add PodSecurityPolicy chart" 2019-01-10 07:24:16 +00:00
Evgeny L
8662018a4d Fix json parsing error for rally config
Change-Id: If573af721df73dd791bbf3b9bd5272ae8453aaa5
2019-01-09 15:25:25 +00:00
Zuul
f743caa254 Merge "Fix rally deployment config to rally 1.3.0" 2019-01-09 06:16:01 +00:00
Zuul
13124286e2 Merge "Kibana: Include kernel and journal indexes in register job" 2019-01-08 23:51:28 +00:00
Zuul
2a3740f349 Merge "[CEPH] Directory OSD regression fix" 2019-01-08 22:17:50 +00:00
Zuul
12f4ff4998 Merge "[Calico] Update comment URL references" 2019-01-08 21:06:37 +00:00
Zuul
90542c5c29 Merge "[CEPH] select the RGW backend based on RGW version" 2019-01-08 20:50:26 +00:00
Matthew Heler
e9c7aab6fd [CEPH] Directory OSD regression fix
Fix a regression with the Directory OSD logic.

Change-Id: I793cf0869bda5c640eb945cbb8190cd89b30c4d0
2019-01-08 13:45:32 -06:00
Steve Wilkerson
6a78fa2eae Kibana: Include kernel and journal indexes in register job
This updates the Kibana chart to include the kernel and journal
indexes as part of the default indexes that get registered with
the register-indexes job

Change-Id: Icd8678debb3dd9620548c6a7c5f02dbb1da048ba
2019-01-08 13:11:18 -06:00
Zuul
1c6d48f4a5 Merge "Selenium Tests for OSH Infra" 2019-01-08 18:03:17 +00:00
Zuul
bc462c83cc Merge "Correct the test for proxy.http" 2019-01-08 16:59:31 +00:00
Matthew Heler
ec86891c8f [CEPH] select the RGW backend based on RGW version
Use the Beast backend only when Mimic binaries are installed.
Otherwise use civitweb if the binares are from Ceph Luminous.

Change-Id: Ia7cb64d8db7eed2fc0c57387b26a27163af34520
2019-01-08 10:19:26 -06:00
Zuul
7bc6f0adbd Merge "[CEPH] OSD directory permission fixes" 2019-01-08 07:07:15 +00:00
Chris Wedgwood
016eba093c [Calico] Update comment URL references
Update the comment URL references to v3.4 to match the code; other
than ipPool (which was extended) the previous objects versions match
the current version.

Change-Id: I1dae92c99992e3a808bea2c270b9d6070274e9f6
2019-01-08 06:25:58 +00:00
chengli3
17108b7d95 Correct the test for proxy.http
proxy.http | trim returns "None" instead of "". To test if proxy should
be used, when: proxy.http should be good enough.
We don't have to test if proxy.http is defined or not. Because it is
alredy defined in defaults/main.yaml.

Change-Id: Ia6330907d22c3f46586aec16db3eefab1a5bbac9
Task: 28755
Story: 2004717
2019-01-08 12:33:55 +08:00
Matthew Heler
4a85c21996 [CEPH] OSD directory permission fixes
In the event the base image is changed, the uid of the ceph OSD
directory may not align with the uid of the ceph user of the image.
In this case we check permissions and set them correctly.

Change-Id: I3bef7f6323d1de7c62320ccd423c929349bedb42
2019-01-07 19:08:11 -06:00
Zuul
f0388b9adb Merge "Elasticsearch: Update image for s3 bucket creation" 2019-01-07 22:18:36 +00:00
Zuul
9de0d96739 Merge "Fluentd: Add security context for pods/containers" 2019-01-07 22:15:19 +00:00
Zuul
09a65edd69 Merge "Jobs: Move tenant-ceph check to periodic job" 2019-01-07 22:11:00 +00:00
Meg Heisler
c3bef9e88f Selenium Tests for OSH Infra
This adds scripts using Selenium Webdriver to verify
the dashboards for Gafana, Nagios, and Prometheus are
reachable and functioning as expected. The scripts
create screenshots of each dashboard as well as
pages that can be navigated to.

It also adds the scripts to the gates for the single
and multinode deployments.

Change-Id: I1699e0ba8ff82ce8f59342cc71aad10cff7d2516
2019-01-07 15:59:42 -06:00
Steve Wilkerson
290df62223 Elasticsearch: Update image for s3 bucket creation
This updates the Elasticsearch image used for s3 bucket creation
to use the same ceph daemon image used in the ceph-rgw chart now
that the Mimic release is supported

Change-Id: I416a283b8ac41f6b360d20aac1be8374c07badcd
2019-01-07 13:51:55 -06:00
Zuul
1c87af7856 Merge "Grafana: Add container security context" 2019-01-07 19:40:22 +00:00
Zuul
9a1a2aea8f Merge "Openstack exporter: Add security context for pod/container" 2019-01-07 19:40:21 +00:00
Zuul
632742b5f7 Merge "Remove unused pod-etc-apache volumes" 2019-01-07 19:40:20 +00:00
Zuul
4f9a6030c4 Merge "Grafana: Add dashboard for coredns" 2019-01-07 19:40:10 +00:00
Zuul
0223b1f91c Merge "Mariadb: Add security context for mysql exporter pod/container" 2019-01-07 16:30:36 +00:00
Zuul
4c4445aadf Merge "Memcached: Add security context for exporter pod/container" 2019-01-07 16:30:35 +00:00
Zuul
737327482f Merge "Alertmanager: Add security context for pod/container" 2019-01-07 16:30:34 +00:00
Zuul
5347636108 Merge "Elasticsearch: Add security context for exporter pod/container" 2019-01-07 16:26:08 +00:00
Zuul
0770465962 Merge "Uplift Ceph charts to the Mimic release" 2019-01-05 19:39:57 +00:00
Zuul
b70fe971c5 Merge "Helm-toolkit: Update job for creating s3 buckets" 2019-01-05 19:36:35 +00:00
Matthew Heler
c0d028e245 Uplift Ceph charts to the Mimic release
Change the release of Ceph from 12.2.3 (Luminous) to latest 13.2.2
(Mimic). Additionally use supported RHEL/Centos Images rather then
Ubuntu images, which are now considered deprecated by Redhat.

- Uplift all Ceph images to the latest 13.2.2 ceph-container images.
- RadosGW by default will now use the Beast backend.
- RadosGW has relaxed settings enabled for S3 naming conventions.
- Increased RadosGW resource limits due to backend change.
- All Luminous specific tests now test for both Luminous/Mimic.
- Gate scripts will remove all none required ceph packages. This is
required to not conflict with the pid/gid that the Redhat container
uses.

Change-Id: I9c00f3baa6c427e6223596ade95c65c331e763fb
2019-01-05 14:38:38 +00:00
Steve Wilkerson
8180635733 Helm-toolkit: Update job for creating s3 buckets
This updates the helm-toolkit manifest template and scipts for
creating an S3 bucket and linking it to a user. This moves away
from the previous python implementation that used rgwadmin, and
instead uses s3cmd for a cleaner approach that can support more
recent versions of ceph

Change-Id: I305062a5daa063bfe21a12448d7a3957bca00bf4
2019-01-05 14:37:47 +00:00
Zuul
ff51fd77e1 Merge "Parameterize hugepage pod cgroup" 2019-01-05 09:17:11 +00:00
weiyj
f5d1d6938c spelling error
Change-Id: Idd9e6bc6a1459e74703599b94f0b410fdb9f94ef
2019-01-05 04:39:23 +00:00
Zuul
754758e8a7 Merge "Kube-State-Metrics: Add pod/container security context" 2019-01-05 03:14:11 +00:00
Steve Wilkerson
7788a1ebea Grafana: Add dashboard for coredns
This adds a Grafana dashboard for coredns metrics

Change-Id: I5b6698675fad2562741569de559419a1898523ee
2019-01-04 12:00:04 -06:00
Steve Wilkerson
2716e01c3f Jobs: Move tenant-ceph check to periodic job
This moves the tenant-ceph job from a check to a periodic job

Change-Id: I01e8df6e9d4b39859db32526c29b6397df14e21f
2019-01-04 11:39:56 -06:00
Steve Wilkerson
30d2cf00d4 Remove unused pod-etc-apache volumes
This removes unused pod-etc-apache volumes from the charts that
use an apache sidecar container as a reverse proxy.

Change-Id: Ibafff3b53f9d3c20f5aed30d40ee6470cb515a8a
2019-01-04 10:31:35 -06:00
Zuul
0b66795342 Merge "Grafana: Add pod security context for grafana user" 2019-01-04 10:08:33 +00:00
Zuul
9eb31f0374 Merge "'NOP' cleanup for more consistent white-space use in charts" 2019-01-04 07:32:39 +00:00
Zuul
6adecf2bea Merge "Ceph: Fix provisioner name substituation typo" 2019-01-04 05:08:28 +00:00
Chris Wedgwood
0c4e37391f 'NOP' cleanup for more consistent white-space use in charts
Where we have the style '{{ ...' we should use the style '... }}'.

Change-Id: Ic3e779e4681370d396f95d3804ca27db5b9d3642
2019-01-03 22:45:49 +00:00
Steve Wilkerson
bf5840fa7a Grafana: Add container security context
This adds the container security context to grafana, which
explicitly sets allowPrivilegeEscalation to false

Change-Id: I3723a0c96699b9a517dafa2df08bf8cc916bf117
2019-01-03 16:19:03 -06:00
Steve Wilkerson
236d686a6d Openstack exporter: Add security context for pod/container
This adds a security context to the openstack exporter, which
changes the pod's user from root to the nobody user instead

This also adds the container security context to explicitly set
allowPrivilegeEscalation to false

Change-Id: Ie3f105ee8b489f7641b5b7256a2023ae35257343
2019-01-03 16:16:43 -06:00