Files
my-rook-config/tests/scripts/deploy_admission_controller.sh
T

120 lines
4.0 KiB
Bash
Raw Normal View History

#!/usr/bin/env bash
# deploy_admission_controller.sh
# Sets up the environment for the admission controller webhook in the active cluster.
set -eEo pipefail
function cleanup() {
set +e
2021-08-06 12:01:57 +05:30
kubectl -n rook-ceph delete validatingwebhookconfigurations "$WEBHOOK_CONFIG_NAME"
kubectl -n rook-ceph delete certificate rook-admission-controller-cert
kubectl -n rook-ceph delete issuers selfsigned-issuer
2021-08-06 12:01:57 +05:30
kubectl delete -f https://github.com/jetstack/cert-manager/releases/download/"$CERT_VERSION"/cert-manager.yaml
set -e
}
2021-05-26 14:44:06 +05:30
function error_log() {
set +e -x
2021-05-26 14:55:27 +05:30
kubectl -n rook-ceph get issuer
2021-05-26 14:44:06 +05:30
kubectl -n rook-ceph get certificate
kubectl -n rook-ceph get secret | grep rook-ceph-admission-controller
2021-08-06 12:01:57 +05:30
kubectl -n rook-ceph get validatingwebhookconfigurations.admissionregistration.k8s.io
kubectl describe validatingwebhookconfigurations.admissionregistration.k8s.io cert-manager-webhook
kubectl describe validatingwebhookconfigurations.admissionregistration.k8s.io rook-ceph-webhook
2021-05-26 14:44:06 +05:30
kubectl -n cert-manager logs deploy/cert-manager-webhook --tail=10
kubectl -n cert-manager logs deploy/cert-manager-cainjector --tail=10
set -e +x
cleanup
}
2021-08-06 12:01:57 +05:30
trap cleanup SIGINT
2021-05-26 14:44:06 +05:30
trap error_log ERR
2021-03-05 16:39:52 +05:30
# Minimum 1.16.0 kubernetes version is required to start the admission controller
SERVER_VERSION=$(kubectl version --short | awk -F "." '/Server Version/ {print $2}')
MINIMUM_VERSION=16
2021-08-06 12:01:57 +05:30
if [ "${SERVER_VERSION}" -lt ${MINIMUM_VERSION} ]; then
2021-03-05 16:39:52 +05:30
echo "required minimum kubernetes version 1.$MINIMUM_VERSION.0"
exit
fi
# Set our known directories and parameters.
BASE_DIR=$(cd "$(dirname "$0")"; pwd)
2021-05-26 14:55:27 +05:30
CERT_VERSION="v1.3.1"
[ -z "${NAMESPACE}" ] && NAMESPACE="rook-ceph"
export NAMESPACE
export WEBHOOK_CONFIG_NAME="rook-ceph-webhook"
export SERVICE_NAME="rook-ceph-admission-controller"
echo "$BASE_DIR"
2021-05-26 14:44:06 +05:30
echo "Deploying cert-manager"
kubectl apply -f https://github.com/jetstack/cert-manager/releases/download/$CERT_VERSION/cert-manager.yaml
2021-08-06 12:01:57 +05:30
timeout 150 bash <<-'EOF'
until [ $(kubectl -n cert-manager get pods --field-selector=status.phase=Running | grep -c ^cert-) -eq 3 ]; do
echo "waiting for cert-manager pods to be in running state"
sleep 1
done
EOF
timeout 20 bash <<-'EOF'
until [ $(kubectl -n cert-manager get pods -o custom-columns=READY:status.containerStatuses[*].ready | grep -c true) -eq 3 ]; do
echo "waiting for the pods to be in ready state"
sleep 1
done
EOF
timeout 25 bash <<-'EOF'
until [ $(kubectl get validatingwebhookconfigurations cert-manager-webhook -o jsonpath='{.webhooks[*].clientConfig.caBundle}' | wc -c) -gt 1 ]; do
echo "waiting for caInjector to inject in caBundle for cert-manager validating webhook"
sleep 1
done
EOF
timeout 25 bash <<-'EOF'
until [ $(kubectl get mutatingwebhookconfigurations cert-manager-webhook -o jsonpath='{.webhooks[*].clientConfig.caBundle}' | wc -c) -gt 1 ]; do
echo "waiting for caInjector to inject in caBundle for cert-managers mutating webhook"
sleep 1
done
EOF
2021-05-26 14:44:06 +05:30
echo "Successfully deployed cert-manager"
2021-05-26 14:44:06 +05:30
echo "Creating Issuer and Certificate"
cat <<EOF | kubectl create -f -
apiVersion: cert-manager.io/v1
kind: Issuer
metadata:
name: selfsigned-issuer
namespace: ${NAMESPACE}
spec:
selfSigned: {}
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: rook-admission-controller-cert
namespace: ${NAMESPACE}
spec:
dnsNames:
- ${SERVICE_NAME}
- ${SERVICE_NAME}.${NAMESPACE}.svc
- ${SERVICE_NAME}.${NAMESPACE}.svc.cluster.local
issuerRef:
kind: Issuer
name: selfsigned-issuer
secretName: rook-ceph-admission-controller
EOF
2021-05-26 14:44:06 +05:30
echo "Successfully created Issuer and Certificate"
echo "Deploying webhook config"
2021-08-06 12:01:57 +05:30
< "${BASE_DIR}"/webhook-config.yaml \
"${BASE_DIR}"/webhook-patch-ca-bundle.sh | \
sed -e "s|\${NAMESPACE}|${NAMESPACE}|g" | \
sed -e "s|\${WEBHOOK_CONFIG_NAME}|${WEBHOOK_CONFIG_NAME}|g" | \
sed -e "s|\${SERVICE_NAME}|${SERVICE_NAME}|g" | \
kubectl create -f -
echo "Webhook deployed! Please start the rook operator to create the service and admission controller pods"