1288 Commits

Author SHA1 Message Date
Zuul
c205f6cba7 Merge "Add podsecuritypolicy test" 2019-03-07 22:33:20 +00:00
Zuul
43ae215ca9 Merge "Elasticsearch: Add check to job for registering snapshot repo" 2019-03-07 20:19:57 +00:00
Zuul
6497dd568a Merge "readOnlyRootFilesystem: true for Prometheus chart" 2019-03-07 19:19:21 +00:00
Zuul
7416a4bc36 Merge "readOnlyRootFilesystem: true for Prometheus exporters charts" 2019-03-07 19:13:06 +00:00
Zuul
070c3e5959 Merge "readOnlyFilesystem: true for elasticsearch chart" 2019-03-07 19:13:05 +00:00
Zuul
3d84a612f9 Merge "readOnlyFilesystem: true for fluent-logging chart" 2019-03-07 19:02:31 +00:00
Zuul
653f46be3c Merge "Add seccomp annotation function" 2019-03-07 19:02:30 +00:00
Zuul
0e8c8ff6f5 Merge "readOnlyRootFilesystem: true for Calico chart" 2019-03-07 19:00:32 +00:00
Zuul
0171373e86 Merge "readOnlyFilesystem: true for nagios chart" 2019-03-07 18:14:11 +00:00
Rahul Khiyani
bfa58f9177 readOnlyRootFilesystem: true for Prometheus chart
Fix for adding readOnlyRootFilesystem flag at pod
level

Change-Id: I04079be87780292da1bf9b2142f0a01a8b575b5b
2019-03-07 17:42:48 +00:00
Rahul Khiyani
ab86685bea readOnlyFilesystem: true for elasticsearch chart
Fix for adding readOnlyFilesystem flag at pod
level

Change-Id: Ife8d2b5ea02b4734ee4a83e868e16831e5f2b23f
2019-03-07 17:13:08 +00:00
Rahul Khiyani
be45316771 readOnlyFilesystem: true for fluent-logging chart
Fix for adding readOnlyFilesystem flag at pod
level

Change-Id: I29224a4f0a6a9ac98dd6016eaf7215a99230328e
2019-03-07 17:12:04 +00:00
Rahul Khiyani
5b513d333f readOnlyRootFilesystem: true for Prometheus exporters charts
Fix for adding readOnlyRootFilesystem flag at pod
level

Change-Id: I3d81f9dca7e1bce0134a39a96b96ef7712d28d84
2019-03-07 17:10:39 +00:00
Hemanth Nakkina
2d0d850d59 Add seccomp annotation function
Adds seccomp annotation function in helm toolkit.
This function can be used by charts to add seccomp
annotations in containers metadata section.

Change-Id: Icf36f1e4aff36fec8a9eefaff06d12984aeb7a78
2019-03-07 17:04:43 +00:00
Rahul Khiyani
7520f9b8e7 readOnlyRootFilesystem: true for Calico chart
Fix for adding readOnlyRootFilesystem flag at pod
level

Change-Id: I79fd55e582487ffe91a750a51c7a2c5bed13f777
2019-03-07 15:19:47 +00:00
Zuul
e836707ad0 Merge "Add east-west ingress network policy to Prometheus" 2019-03-07 04:44:10 +00:00
Zuul
6f6783bf23 Merge "Add ingress network policy for Nagios" 2019-03-07 04:36:14 +00:00
Zuul
2f8d4e5bd7 Merge "[ceph-osd] fix ceph journal partition creation" 2019-03-06 20:44:34 +00:00
Meg Heisler
736af38c9c Add ingress network policy for Nagios
This adds the ingress network policy to Nagios
using the helm-toolkit template

Change-Id: If6cc66330b24c3f79f9b5c29a94ea904d1eb37d4
2019-03-06 12:42:29 -06:00
Meg Heisler
243f6c7608 Add east-west ingress network policy to Prometheus
This adds an ingress policy to Prometheus and utilizes
the helm-toolkit used in openstack-helm

Change-Id: Ia89d42a5305c94da26337aaf716978c1defae503
2019-03-06 11:56:13 -06:00
Zuul
dc6f37b0af Merge "Implement Security Context for Memcached" 2019-03-06 16:39:51 +00:00
Zuul
bc87f20029 Merge "(postgresql) Add Helm test" 2019-03-06 16:32:01 +00:00
Zuul
6c29e00d1d Merge "HTK: Refactor kubernetes security_context macro(s) to allow scoping" 2019-03-06 15:23:01 +00:00
Zuul
5c7af7e3d9 Merge "readOnlyRootFilesystem: true for openvswitch chart" 2019-03-06 15:22:54 +00:00
Zuul
07c005909b Merge "ceph-rgw: Add network policy for ceph-rgw pods" 2019-03-06 15:21:22 +00:00
Chinasubbareddy Mallavarapu
6feb7d7624 [ceph-osd] fix ceph journal partition creation
This is to run partprobe command after ceph journal
partition creation.

Change-Id: Ia9acd26adf781b4508ef7028f613350077f7a970
2019-03-06 07:54:36 -06:00
Scott Hussey
43a93e2cbd (postgresql) Add Helm test
- Add a Helm test for testing DDL and DML for Postgres

Change-Id: Ib34ea48abf836ae52b909b30fdb8275d80a3c559
2019-03-06 06:36:51 +00:00
Cliff Parsons
8bbe8452c2 Implement Security Context for Memcached
Implement a pod security context for the following Memcached resources:
 - Memcached server deployment

Change-Id: I8628ceb246e7c435a2ddd20bf1bcecd94db8ea26
2019-03-06 06:35:11 +00:00
Rahul Khiyani
598040bea0 readOnlyRootFilesystem: true for openvswitch chart
Fix for adding readOnlyRootFilesystem flag at pod
level

Change-Id: If0943518bdec0d950c50c90aa89929d1a42aa0a0
2019-03-06 04:36:02 +00:00
Zuul
8fb2c7f07c Merge "Fix wrong command for validation check" 2019-03-06 04:03:32 +00:00
Zuul
21e4fa4105 Merge "[CEPH] RGW tuning for Mimic release" 2019-03-06 04:02:48 +00:00
Zuul
c8fcdeaddf Merge "Deep copy daemonset_yaml cross loop" 2019-03-06 03:50:09 +00:00
Zuul
15ff3d6ae9 Merge "(postgresql) set db admin password at startup" 2019-03-06 03:42:37 +00:00
Steve Wilkerson
f361fd6477 Elasticsearch: Add check to job for registering snapshot repo
This updates the script used to register the elasticsearch
snapshot repositories. It will first gather a list of all
currently registered repositories, then check for the existence
of each configured repository.  If the repository exists, the job
will not attempt to register the repository again. If it doesn't
exist, the job will then register the desired repository

Change-Id: I2cfd3c44f1b2b4a54c9b07be79c2c87af77c540e
2019-03-06 03:09:27 +00:00
Chinasubbareddy M
babe91b75e ceph-rgw: Add network policy for ceph-rgw pods
This is to add ingress network policy for ceph-rgw pods

Change-Id: I32a5d3d9a05b920bc69d5b5bb5a2d27cf6f55542
2019-03-06 03:08:34 +00:00
Pete Birley
9ec2910151 HTK: Refactor kubernetes security_context macro(s) to allow scoping
This PS updates the kubernetes_pod_security_context snippet, and adds a
macro for container securityContexts
'kubernetes_container_security_context.

Change-Id: I8b9c7b72f836efaf6c9dc3ad20fd8462b0d06d77
Signed-off-by: Pete Birley <pete@port.direct>
2019-03-05 21:42:25 +00:00
Scott Hussey
4a505e213c (postgresql) set db admin password at startup
- Make the default to run the postgres database as the uid 999 which
  the default image maps to the 'postgres' user

- If the database is already initialized, before starting postgres
  set the 'postgres' database user password to match the declared
  intended password

Change-Id: I7b0ea7a86246b098f38ef4c03dd157731f61e066
2019-03-05 18:38:41 +00:00
Chinasubbareddy Mallavarapu
47d429059c [ceph-osd] resolve name conflicts by appending release name
This is to resolve name conflicts of reources in case of multiple
releases required for single deployment of ceph cluster

Change-Id: Ibee5550db788ea57879837b010e22a24240237bf
2019-03-04 22:39:03 -06:00
Rahul Khiyani
e20242fbdb readOnlyFilesystem: true for nagios chart
Fix for adding readOnlyFilesystem flag at pod
level

Change-Id: I1b70d0537a6561ca1e521d52b331b50bc7b2c3dc
2019-03-04 17:21:09 +00:00
Zuul
2eb745d53a Merge "Update irc meeting channel" 2019-03-04 17:17:14 +00:00
Zuul
14713b54e7 Merge "Add support for PostgreSQL DB Initialization" 2019-03-04 17:11:43 +00:00
Matthew Heler
66cb979bc2 [CEPH] RGW tuning for Mimic release
Remove overrides that are already set or raised higher in the
Mimic release of Ceph for RGW.

rgw_thread_pool_size is now by default using 512
objecter_inflight_ops is now also set to 24576 by default for RGW

Change-Id: I982f6bc08954864afa5ad29923707e1bf64ba9fa
2019-03-01 06:54:47 +00:00
Matt McEuen
84333745e2 Add podsecuritypolicy test
This adds a test for the podsecuritypolicy chart, as well as a script
to reconfigure minikube with PodSecurityPolity enabled when appropriate.

This change doesn't add the PSP chart to the existing tests, because
the psp chart will have secure defaults in the future, which may
interfere with other charts by default; and it doesn't enable the
admission controller broadly, because turning the AC on without
providing a podsecuritypolicy will break k8s functionality.

Change-Id: I9fd14bb118189cd4ead177b79e39aadbc2096b4a
2019-02-28 16:40:24 -06:00
Zuul
0f176e2455 Merge "Add default-docker (enforce) AppArmor profile to Elasticsearch" 2019-02-28 20:42:46 +00:00
Zuul
a367bacb4b Merge "readOnlyFilesystem: true for memcached chart" 2019-02-27 19:15:01 +00:00
Zuul
c14e4084c3 Merge "readOnlyFilesystem: true for rabbitmq chart" 2019-02-27 19:15:00 +00:00
Zuul
7e26ed1b20 Merge "readOnlyFilesystem: true for ingress chart" 2019-02-27 19:09:30 +00:00
chengli3
f7b8826799 Update irc meeting channel
Update irc meeting channel to #openstack-meeting-4

Change-Id: Icc4b5793ca7fcadd848fa1e7afdda01ba064a92c
2019-02-27 15:02:06 +08:00
Zuul
a88fae1fbb Merge "Update logging format and config for apache reverse proxies" 2019-02-27 01:33:35 +00:00
Rahul Khiyani
25a86df489 readOnlyFilesystem: true for rabbitmq chart
Fix for adding readOnlyFilesystem flag at pod level

Change-Id: I30ef83f1e381d24f40bfc92a1e740746135eceab
2019-02-27 00:24:19 +00:00