magnum merge requestshttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests2023-06-09T09:13:22+02:00https://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/238[cern] move k8s-keystone-auth to helm2023-06-09T09:13:22+02:00Ricardo Rocha[cern] move k8s-keystone-auth to helmRicardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/237[cern] move ci artifacts to registry.cern.ch/kubernetes2023-06-09T09:19:31+02:00Ricardo Rocha[cern] move ci artifacts to registry.cern.ch/kubernetesRicardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/236[cern] Add support for arm64 builds2023-06-09T09:11:24+02:00Ricardo Rocha[cern] Add support for arm64 buildsThis works with docker buildx with --platform linux/amd64,linux/arm64
--build-arg v3.2.0 ...This works with docker buildx with --platform linux/amd64,linux/arm64
--build-arg v3.2.0 ...https://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/235[cern] Fix CERN Grid Certification download path2023-06-08T08:16:34+02:00Diogo Filipe Tomas Guerra[cern] Fix CERN Grid Certification download pathDue to a new certificate, when magnum installs the CERN certificates
(even when cern_enabled is false) fails because the replcaed certificate
was removed and the file cannot be downloaded.
When we trying to update-ca-trust this operatio...Due to a new certificate, when magnum installs the CERN certificates
(even when cern_enabled is false) fails because the replcaed certificate
was removed and the file cannot be downloaded.
When we trying to update-ca-trust this operation fails and cluster
fails to create. Using the new file path should be a quick fix for this
Change-Id: Ie3d1e0049d859828377963ef25d8e9dcb79a7dd5Diogo Filipe Tomas GuerraDiogo Filipe Tomas Guerrahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/234[cern] Fix policy for admin certificate sign2023-06-08T08:20:00+02:00Ricardo Rocha[cern] Fix policy for admin certificate signRicardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/233[cern] use cluster trust in barbican context2023-06-08T08:19:00+02:00Ricardo Rocha[cern] use cluster trust in barbican contextR-2023-Q3-1Ricardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/232move CI to magnum repo2023-03-20T08:40:52+01:00Ricardo Rochamove CI to magnum repoRicardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/231[cern] make helm client version configuration for cern-chart2023-06-09T17:32:25+02:00Ricardo Rocha[cern] make helm client version configuration for cern-chartR-2023-Q3-1Ricardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/230[cern] drop etcd load balancer2023-03-20T16:13:56+01:00Ricardo Rocha[cern] drop etcd load balancerR-2023-Q3-1Ricardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/229[cern] Add nfs_csi_enabled label2023-06-09T10:54:14+02:00Robert Vasek[cern] Add nfs_csi_enabled labelThis MR adds `nfs_csi_enabled` cluster template label. Its value is then passed to csi-driver-nfs.enabled cern-magnum Helm value.This MR adds `nfs_csi_enabled` cluster template label. Its value is then passed to csi-driver-nfs.enabled cern-magnum Helm value.R-2023-Q3-1Robert VasekRobert Vasekhttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/228Change cern-magnum.sh to allow value substitution2023-11-21T15:28:03+01:00Diogo Filipe Tomas GuerraChange cern-magnum.sh to allow value substitutionWhen using --label cern_chart_values, the values under ${} will be replaced
by the values in the heat_template_parameters file.
In addition to this, the bash commands $() will not be executed and thus
cluster bring up will not work.
Als...When using --label cern_chart_values, the values under ${} will be replaced
by the values in the heat_template_parameters file.
In addition to this, the bash commands $() will not be executed and thus
cluster bring up will not work.
Also added commit of other missing values into the heat-params
Closes: https://gitlab.cern.ch/kubernetes/magnum/-/issues/25
Change-Id: I1c8aa825b607da778967b4b7f8e3de15fd3a8db1R-2023-Q4-1Diogo Filipe Tomas GuerraDiogo Filipe Tomas Guerrahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/227[cern] set cern-magnum helm install timeout to 15m2023-02-01T11:57:24+01:00Ricardo Rocha[cern] set cern-magnum helm install timeout to 15mCloses #24.Closes #24.R-2023-Q1-0Ricardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/226[cern] Fix cern-chart cvmfs-csi values section name2023-01-31T08:47:14+01:00Ricardo Rocha[cern] Fix cern-chart cvmfs-csi values section nameR-2023-Q1-0Ricardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/225disable prometheus adapter when monitoring_enabled is false2023-01-31T22:06:40+01:00Diogo Filipe Tomas Guerradisable prometheus adapter when monitoring_enabled is falseFrom: https://cern.service-now.com/nav_to.do?uri=incident.do?sysparm_query=number=INC3365942%26sysparm_view=it_operations_management
Not sure we want to add this. When we where installing with magnum
the validation that monitoring_enabl...From: https://cern.service-now.com/nav_to.do?uri=incident.do?sysparm_query=number=INC3365942%26sysparm_view=it_operations_management
Not sure we want to add this. When we where installing with magnum
the validation that monitoring_enabled was true was happening when installing
the prometheus-adapter but not when we moved to helm.
There is a label for prometheus_adapter_enabled so maybe this is not usefull.R-2023-Q1-0Diogo Filipe Tomas GuerraDiogo Filipe Tomas Guerrahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/224integrate tn patches into main branch2023-06-05T15:12:24+02:00Ricardo Rochaintegrate tn patches into main branchThis should disable the discovery url and bootstrap a fresh etcd
staticallyThis should disable the discovery url and bootstrap a fresh etcd
staticallyR-2023-Q3-1Ricardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/223Fix cern enable autoscaler label not working2023-02-01T20:47:00+01:00Diogo Filipe Tomas GuerraFix cern enable autoscaler label not workingWhen the original commit by @stavros was merged into
cern/train we seem to have droped some configurations
and also, enabling the autoscaler in the cern-magnum
was not set. This patch fixes this issues
Closes: https://gitlab.cern.ch/kub...When the original commit by @stavros was merged into
cern/train we seem to have droped some configurations
and also, enabling the autoscaler in the cern-magnum
was not set. This patch fixes this issues
Closes: https://gitlab.cern.ch/kubernetes/magnum/-/issues/14
Change-Id: Ice5e597386e612ffed20091b79c5ca5e35737b74
EDIT: looks like the last push of this branch was not merged
into magnum and the original commit was what was merged, and
this is not working.
Closes: https://gitlab.cern.ch/kubernetes/magnum/-/issues/14Diogo Filipe Tomas GuerraDiogo Filipe Tomas Guerrahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/222drop logtostderr config option2023-01-31T21:42:33+01:00Ricardo Rochadrop logtostderr config optionThis option has been removed in 1.26.This option has been removed in 1.26.R-2023-Q1-0Ricardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/221Infere dns_service_ip from service_cluster_ip_range2023-11-27T08:51:02+01:00Radu CarpaInfere dns_service_ip from service_cluster_ip_rangewhen setting a custom service_cluster_ip_range label,
the default cluster dns service ip (10.254.0.10) may
end being outside the service IP range which results
in DNS not working in the cluster.
Heat templates already support setting th...when setting a custom service_cluster_ip_range label,
the default cluster dns service ip (10.254.0.10) may
end being outside the service IP range which results
in DNS not working in the cluster.
Heat templates already support setting the needed
variable. Automatically take the 10th ip address
from the service range. This should fix the issue
of DNS not working for people who set the
service_cluster_ip_range label while keeping things
unchanged for those who don't set it.R-2023-Q4-1Ricardo RochaRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/220[cern] Don't relabel /var/lib/kubelet in kubelet.service unit2023-01-23T10:16:02+01:00Robert Vasek[cern] Don't relabel /var/lib/kubelet in kubelet.service unitCSI volume mounts used by Pods live under:
* `/var/lib/kubelet/plugins/kubernetes.io/csi/pv/<PV>/globalmount`
* `/var/lib/kubelet/pods/<POD>/volumes/kubernetes.io~csi/<PV>/mount`
If the filesystem of the mounted volume doesn't support x...CSI volume mounts used by Pods live under:
* `/var/lib/kubelet/plugins/kubernetes.io/csi/pv/<PV>/globalmount`
* `/var/lib/kubelet/pods/<POD>/volumes/kubernetes.io~csi/<PV>/mount`
If the filesystem of the mounted volume doesn't support xattrs (e.g. FUSE),
relabeling fails, and `podman run` exits with error.
`/var/lib/kubelet` may still need to be relabeled, but maybe we can do this at node creation time?
Closes: https://gitlab.cern.ch/kubernetes/magnum/-/issues/19R-2022-Q3-1Ricardo RochaSpyridon TrigazisDiogo Filipe Tomas GuerraRicardo Rochahttps://gitlab.cern.ch/kubernetes/magnum/-/merge_requests/219[cern] Allow OS magnum admin to get cluster certificate2023-03-03T14:53:36+01:00Diogo Filipe Tomas Guerra[cern] Allow OS magnum admin to get cluster certificateCloses: https://gitlab.cern.ch/kubernetes/project/-/issues/153
Change-Id: Ibc02c96e94be33e4329fc71a382d3bb1e953f96bCloses: https://gitlab.cern.ch/kubernetes/project/-/issues/153
Change-Id: Ibc02c96e94be33e4329fc71a382d3bb1e953f96bR-2023-Q3-1Diogo Filipe Tomas GuerraDiogo Filipe Tomas Guerra