Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Helm: add ruler specific service account #7132

Merged
merged 15 commits into from
Feb 8, 2024
Merged
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions operations/helm/charts/mimir-distributed/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ Entries should include a reference to the Pull Request that introduced the chang
* [ENHANCEMENT] Rollout-operator: upgraded to v0.10.1. #7125
* [ENHANCEMENT] Query-frontend: configured `-shutdown-delay`, `-server.grpc.keepalive.max-connection-age` and termination grace period to reduce the likelihood of queries hitting terminated query-frontends. #7129
* [BUGFIX] Metamonitoring: update dashboards to drop unsupported `step` parameter in targets. #7157
* [ENHANCEMENT] Add the possibility to create a dedicated serviceAccount for the `ruler` component.
dimitarvdimitrov marked this conversation as resolved.
Show resolved Hide resolved

## 5.2.0

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,7 @@ For compatibility and to support upgrade from enterprise-metrics chart calculate
{{- end -}}

{{/*
Create the name of the service account
Create the name of the general service account
*/}}
{{- define "mimir.serviceAccountName" -}}
{{- if .Values.serviceAccount.create -}}
Expand All @@ -74,6 +74,18 @@ Create the name of the service account
{{- end -}}
{{- end -}}

{{/*
Create the name of the ruler service account
*/}}
{{- define "mimir.ruler.serviceAccountName" -}}
{{- if .Values.serviceAccount.create -}}
dimitarvdimitrov marked this conversation as resolved.
Show resolved Hide resolved
{{- $sa := default (include "mimir.fullname" .) .Values.serviceAccount.name }}
dimitarvdimitrov marked this conversation as resolved.
Show resolved Hide resolved
{{- printf "%s-%s" $sa "ruler" }}
dimitarvdimitrov marked this conversation as resolved.
Show resolved Hide resolved
{{- else -}}
{{ default (include "mimir.serviceAccountName" .) .Values.serviceAccount.name }}
dimitarvdimitrov marked this conversation as resolved.
Show resolved Hide resolved
{{- end -}}
{{- end -}}

{{/*
Create the app name for clients. Defaults to the same logic as "mimir.fullname", and default client expects "prometheus".
*/}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ spec:
{{- include "mimir.podAnnotations" (dict "ctx" . "component" "ruler") | nindent 8 }}
namespace: {{ .Release.Namespace | quote }}
spec:
serviceAccountName: {{ template "mimir.serviceAccountName" . }}
serviceAccountName: {{ template "mimir.ruler.serviceAccountName" . }}
{{- if .Values.ruler.priorityClassName }}
priorityClassName: {{ .Values.ruler.priorityClassName }}
{{- end }}
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{{- if .Values.ruler.serviceAccount.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ template "mimir.serviceAccountName" . }}
dimitarvdimitrov marked this conversation as resolved.
Show resolved Hide resolved
labels:
{{- include "mimir.labels" (dict "ctx" .) | nindent 4 }}
{{- with .Values.ruler.serviceAccount.labels }}
{{- toYaml . | nindent 4 }}
{{- end }}
annotations:
{{- toYaml .Values.ruler.serviceAccount.annotations | nindent 4 }}
namespace: {{ .Release.Namespace | quote }}
{{- end }}
6 changes: 6 additions & 0 deletions operations/helm/charts/mimir-distributed/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1118,6 +1118,12 @@
service:
annotations: {}
labels: {}

Check failure on line 1121 in operations/helm/charts/mimir-distributed/values.yaml

View workflow job for this annotation

GitHub Actions / call-lint-test / lint-test

[trailing-spaces] trailing spaces
serviceAccount:
create: true
name:
annotations: {}
labels: {}
dimitarvdimitrov marked this conversation as resolved.
Show resolved Hide resolved

resources:
requests:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: enterprise-https-values-mimir
serviceAccountName: enterprise-https-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: enterprise-https-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: enterprise-https-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: gateway-enterprise-values-mimir
serviceAccountName: gateway-enterprise-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: gateway-enterprise-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: gateway-enterprise-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: gateway-nginx-values-mimir
serviceAccountName: gateway-nginx-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: gateway-nginx-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: gateway-nginx-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: graphite-enabled-values-mimir
serviceAccountName: graphite-enabled-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: graphite-enabled-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: graphite-enabled-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: large-values-mimir
serviceAccountName: large-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: large-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: large-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: metamonitoring-values-mimir
serviceAccountName: metamonitoring-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: metamonitoring-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: metamonitoring-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: openshift-values-mimir
serviceAccountName: openshift-values-mimir-ruler
securityContext:
runAsNonRoot: true
seccompProfile:
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: openshift-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: openshift-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: scheduler-name-values-mimir
serviceAccountName: scheduler-name-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: scheduler-name-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: scheduler-name-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: small-values-mimir
serviceAccountName: small-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: small-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: small-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ spec:
minio-secret-version: "42"
namespace: "citestns"
spec:
serviceAccountName: test-enterprise-configmap-values-mimir
serviceAccountName: test-enterprise-configmap-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: test-enterprise-configmap-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: test-enterprise-configmap-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: test-enterprise-k8s-1.25-values-mimir
serviceAccountName: test-enterprise-k8s-1.25-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: test-enterprise-k8s-1.25-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: test-enterprise-k8s-1.25-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: test-enterprise-legacy-label-values-enterprise-metrics
serviceAccountName: test-enterprise-legacy-label-values-enterprise-metrics-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: test-enterprise-legacy-label-values-enterprise-metrics
labels:
app: enterprise-metrics
heritage: Helm
release: test-enterprise-legacy-label-values
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: test-enterprise-values-mimir
serviceAccountName: test-enterprise-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: test-enterprise-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: test-enterprise-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
annotations:
namespace: "citestns"
spec:
serviceAccountName: test-ingress-values-mimir
serviceAccountName: test-ingress-values-mimir-ruler
securityContext:
fsGroup: 10001
runAsGroup: 10001
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
# Source: mimir-distributed/templates/ruler/ruler-sa.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: test-ingress-values-mimir
labels:
app.kubernetes.io/name: mimir
app.kubernetes.io/instance: test-ingress-values
app.kubernetes.io/managed-by: Helm
annotations:
{}
namespace: "citestns"
Loading
Loading