42d6c2321d
There is currently an issue with deploying single pod mysql clusters in which restarting or killing the pod will result in a crashloopbackoff. The mysql data is indeed lost and the start script (thinking the cluster was alive before due to the grastate configmap) tries to restore the cluster instead of bootstrapping it. Due to this, if the mysql pod is killed or restarted in the CI, we will lose all the mysql data, will not recover, and this results in a broken environment. When volume.use_local_path_for_single_pod.enabled value is set to true, which we will apply on single node/single pod testing, this patch will deploy a local volume for mysql at the location specified under volume.use_local_path_for_single_pod.host_path The data will be kept intact in case there is a pod restart, as it can read the data again, and recover itself. When it is false, which is the default for non-CI, nothing changes, and an empty dir is used. This data WILL be lost upon restart, so it is advised to use volumes instead for production purposes, by setting Values.volume.enabled to true. task: 28729 Change-Id: I6ec0bd1087eb06b92ced7dc56ff5b6a156aad433
260 lines
10 KiB
YAML
260 lines
10 KiB
YAML
{{/*
|
|
Copyright 2017 The Openstack-Helm Authors.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/}}
|
|
|
|
{{- if .Values.manifests.statefulset }}
|
|
{{- $envAll := . }}
|
|
|
|
{{- $serviceAccountName := printf "%s-%s" .Release.Name "mariadb" }}
|
|
{{ tuple $envAll "mariadb" $serviceAccountName | include "helm-toolkit.snippets.kubernetes_pod_rbac_serviceaccount" }}
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1beta1
|
|
kind: Role
|
|
metadata:
|
|
name: {{ $serviceAccountName }}
|
|
namespace: {{ $envAll.Release.Namespace }}
|
|
rules:
|
|
- apiGroups:
|
|
- ""
|
|
resources:
|
|
- configmaps
|
|
verbs:
|
|
- create
|
|
- apiGroups:
|
|
- ""
|
|
resourceNames:
|
|
- {{ printf "%s-%s" .Release.Name "mariadb-state" | quote }}
|
|
resources:
|
|
- configmaps
|
|
verbs:
|
|
- get
|
|
- patch
|
|
- apiGroups:
|
|
- ""
|
|
resourceNames:
|
|
- {{ tuple "oslo_db" "direct" . | include "helm-toolkit.endpoints.hostname_short_endpoint_lookup" }}
|
|
resources:
|
|
- endpoints
|
|
verbs:
|
|
- get
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1beta1
|
|
kind: RoleBinding
|
|
metadata:
|
|
name: {{ $serviceAccountName }}
|
|
namespace: {{ $envAll.Release.Namespace }}
|
|
roleRef:
|
|
apiGroup: rbac.authorization.k8s.io
|
|
kind: Role
|
|
name: {{ $serviceAccountName }}
|
|
subjects:
|
|
- kind: ServiceAccount
|
|
name: {{ $serviceAccountName }}
|
|
namespace: {{ $envAll.Release.Namespace }}
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
# NOTE(portdirect): the statefulset name must match the POD_NAME_PREFIX env var for discovery to work
|
|
name: {{ tuple "oslo_db" "direct" . | include "helm-toolkit.endpoints.hostname_short_endpoint_lookup" }}
|
|
annotations:
|
|
{{ tuple $envAll | include "helm-toolkit.snippets.release_uuid" }}
|
|
configmap-bin-hash: {{ tuple "configmap-bin.yaml" . | include "helm-toolkit.utils.hash" }}
|
|
configmap-etc-hash: {{ tuple "configmap-etc.yaml" . | include "helm-toolkit.utils.hash" }}
|
|
mariadb-dbadmin-password-hash: {{ tuple "secret-dbadmin-password.yaml" . | include "helm-toolkit.utils.hash" }}
|
|
mariadb-sst-password-hash: {{ tuple "secret-dbadmin-password.yaml" . | include "helm-toolkit.utils.hash" }}
|
|
labels:
|
|
{{ tuple $envAll "mariadb" "server" | include "helm-toolkit.snippets.kubernetes_metadata_labels" | indent 4 }}
|
|
spec:
|
|
serviceName: "{{ tuple "oslo_db" "discovery" . | include "helm-toolkit.endpoints.hostname_short_endpoint_lookup" }}"
|
|
podManagementPolicy: "Parallel"
|
|
replicas: {{ .Values.pod.replicas.server }}
|
|
selector:
|
|
matchLabels:
|
|
{{ tuple $envAll "mariadb" "server" | include "helm-toolkit.snippets.kubernetes_metadata_labels" | indent 6 }}
|
|
template:
|
|
metadata:
|
|
labels:
|
|
{{ tuple $envAll "mariadb" "server" | include "helm-toolkit.snippets.kubernetes_metadata_labels" | indent 8 }}
|
|
annotations:
|
|
{{ tuple $envAll | include "helm-toolkit.snippets.release_uuid" | indent 8 }}
|
|
configmap-bin-hash: {{ tuple "configmap-bin.yaml" . | include "helm-toolkit.utils.hash" }}
|
|
configmap-etc-hash: {{ tuple "configmap-etc.yaml" . | include "helm-toolkit.utils.hash" }}
|
|
mariadb-dbadmin-password-hash: {{ tuple "secret-dbadmin-password.yaml" . | include "helm-toolkit.utils.hash" }}
|
|
mariadb-sst-password-hash: {{ tuple "secret-dbadmin-password.yaml" . | include "helm-toolkit.utils.hash" }}
|
|
spec:
|
|
shareProcessNamespace: true
|
|
serviceAccountName: {{ $serviceAccountName }}
|
|
{{ dict "envAll" $envAll "application" "server" | include "helm-toolkit.snippets.kubernetes_pod_security_context" | indent 6 }}
|
|
affinity:
|
|
{{ tuple $envAll "mariadb" "server" | include "helm-toolkit.snippets.kubernetes_pod_anti_affinity" | indent 8 }}
|
|
nodeSelector:
|
|
{{ .Values.labels.server.node_selector_key }}: {{ .Values.labels.server.node_selector_value }}
|
|
initContainers:
|
|
{{ tuple $envAll "mariadb" list | include "helm-toolkit.snippets.kubernetes_entrypoint_init_container" | indent 8 }}
|
|
{{- if .Values.volume.chown_on_start }}
|
|
- name: mariadb-perms
|
|
{{ tuple $envAll "mariadb" | include "helm-toolkit.snippets.image" | indent 10 }}
|
|
{{ dict "envAll" $envAll "application" "server" "container" "perms" | include "helm-toolkit.snippets.kubernetes_container_security_context" | indent 10 }}
|
|
{{ tuple $envAll $envAll.Values.pod.resources.server | include "helm-toolkit.snippets.kubernetes_resources" | indent 10 }}
|
|
command:
|
|
- chown
|
|
- -R
|
|
- "mysql:mysql"
|
|
- /var/lib/mysql
|
|
volumeMounts:
|
|
- name: pod-tmp
|
|
mountPath: /tmp
|
|
- name: mysql-data
|
|
mountPath: /var/lib/mysql
|
|
{{- end }}
|
|
containers:
|
|
- name: mariadb
|
|
{{ tuple $envAll "mariadb" | include "helm-toolkit.snippets.image" | indent 10 }}
|
|
{{ dict "envAll" $envAll "application" "server" "container" "mariadb" | include "helm-toolkit.snippets.kubernetes_container_security_context" | indent 10 }}
|
|
{{ tuple $envAll $envAll.Values.pod.resources.server | include "helm-toolkit.snippets.kubernetes_resources" | indent 10 }}
|
|
env:
|
|
- name: POD_NAMESPACE
|
|
valueFrom:
|
|
fieldRef:
|
|
fieldPath: metadata.namespace
|
|
- name: MARIADB_REPLICAS
|
|
value: {{ .Values.pod.replicas.server | quote }}
|
|
- name: POD_NAME_PREFIX
|
|
value: {{ tuple "oslo_db" "direct" . | include "helm-toolkit.endpoints.hostname_short_endpoint_lookup" }}
|
|
- name: DISCOVERY_DOMAIN
|
|
value: {{ tuple "oslo_db" "discovery" . | include "helm-toolkit.endpoints.hostname_fqdn_endpoint_lookup" }}
|
|
- name: DIRECT_SVC_NAME
|
|
value: {{ tuple "oslo_db" "direct" . | include "helm-toolkit.endpoints.hostname_short_endpoint_lookup" }}
|
|
- name: WSREP_PORT
|
|
value: {{ tuple "oslo_db" "direct" "wsrep" . | include "helm-toolkit.endpoints.endpoint_port_lookup" | quote }}
|
|
- name: STATE_CONFIGMAP
|
|
value: {{ printf "%s-%s" .Release.Name "mariadb-state" | quote }}
|
|
- name: MYSQL_DBADMIN_USERNAME
|
|
value: {{ .Values.endpoints.oslo_db.auth.admin.username }}
|
|
- name: MYSQL_DBADMIN_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: mariadb-dbadmin-password
|
|
key: MYSQL_DBADMIN_PASSWORD
|
|
- name: MYSQL_DBSST_USERNAME
|
|
value: {{ .Values.endpoints.oslo_db.auth.sst.username }}
|
|
- name: MYSQL_DBSST_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: mariadb-dbsst-password
|
|
key: MYSQL_DBSST_PASSWORD
|
|
ports:
|
|
- name: mysql
|
|
protocol: TCP
|
|
containerPort: {{ tuple "oslo_db" "direct" "mysql" . | include "helm-toolkit.endpoints.endpoint_port_lookup" }}
|
|
- name: wsrep
|
|
protocol: TCP
|
|
containerPort: {{ tuple "oslo_db" "direct" "wsrep" . | include "helm-toolkit.endpoints.endpoint_port_lookup" }}
|
|
command:
|
|
- /tmp/start.py
|
|
lifecycle:
|
|
preStop:
|
|
exec:
|
|
command:
|
|
- /tmp/stop.sh
|
|
readinessProbe:
|
|
initialDelaySeconds: 30
|
|
periodSeconds: 30
|
|
timeoutSeconds: 3
|
|
exec:
|
|
command:
|
|
- /tmp/readiness.sh
|
|
volumeMounts:
|
|
- name: pod-tmp
|
|
mountPath: /tmp
|
|
- name: var-run
|
|
mountPath: /var/run/mysqld
|
|
- name: mycnfd
|
|
mountPath: /etc/mysql/conf.d
|
|
- name: mariadb-bin
|
|
mountPath: /tmp/start.py
|
|
subPath: start.py
|
|
readOnly: true
|
|
- name: mariadb-bin
|
|
mountPath: /tmp/stop.sh
|
|
subPath: stop.sh
|
|
readOnly: true
|
|
- name: mariadb-bin
|
|
mountPath: /tmp/readiness.sh
|
|
subPath: readiness.sh
|
|
readOnly: true
|
|
- name: mariadb-etc
|
|
mountPath: /etc/mysql/my.cnf
|
|
subPath: my.cnf
|
|
readOnly: true
|
|
- name: mariadb-etc
|
|
mountPath: /etc/mysql/conf.d/00-base.cnf
|
|
subPath: 00-base.cnf
|
|
readOnly: true
|
|
- name: mariadb-etc
|
|
mountPath: /etc/mysql/conf.d/20-override.cnf
|
|
subPath: 20-override.cnf
|
|
readOnly: true
|
|
- name: mariadb-etc
|
|
mountPath: /etc/mysql/conf.d/99-force.cnf
|
|
subPath: 99-force.cnf
|
|
readOnly: true
|
|
- name: mariadb-secrets
|
|
mountPath: /etc/mysql/admin_user.cnf
|
|
subPath: admin_user.cnf
|
|
readOnly: true
|
|
- name: mysql-data
|
|
mountPath: /var/lib/mysql
|
|
volumes:
|
|
- name: pod-tmp
|
|
emptyDir: {}
|
|
- name: mycnfd
|
|
emptyDir: {}
|
|
- name: var-run
|
|
emptyDir: {}
|
|
- name: mariadb-bin
|
|
configMap:
|
|
name: mariadb-bin
|
|
defaultMode: 0555
|
|
- name: mariadb-etc
|
|
configMap:
|
|
name: mariadb-etc
|
|
defaultMode: 0444
|
|
- name: mariadb-secrets
|
|
secret:
|
|
secretName: mariadb-secrets
|
|
defaultMode: 0444
|
|
{{- if not .Values.volume.enabled }}
|
|
- name: mysql-data
|
|
{{- if .Values.volume.use_local_path_for_single_pod_cluster.enabled }}
|
|
hostPath: {{ .Values.volume.use_local_path_for_single_pod_cluster.host_path }}
|
|
{{- else }}
|
|
emptyDir: {}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- if .Values.volume.enabled }}
|
|
volumeClaimTemplates:
|
|
- metadata:
|
|
name: mysql-data
|
|
spec:
|
|
accessModes: [ "ReadWriteOnce" ]
|
|
resources:
|
|
requests:
|
|
storage: {{ .Values.volume.size }}
|
|
storageClassName: {{ .Values.volume.class_name }}
|
|
{{- end }}
|
|
{{- end }}
|