Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix e2e test for rootless image. #568

Closed
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 13 additions & 6 deletions .github/workflows/e2e.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -114,19 +114,19 @@ jobs:
kind: ClusterConfiguration
apiServer:
extraArgs:
"egress-selector-config-file": "/etc/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
"egress-selector-config-file": "/etc/srv/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
extraVolumes:
- name: egress-selector-config-file
hostPath: "/etc/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
mountPath: "/etc/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
hostPath: "/etc/srv/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
mountPath: "/etc/srv/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
readOnly: true
- name: konnectivity-server
hostPath: "/etc/kubernetes/konnectivity-server"
mountPath: "/etc/kubernetes/konnectivity-server"
hostPath: "/etc/srv/kubernetes/konnectivity-server"
mountPath: "/etc/srv/kubernetes/konnectivity-server"
readOnly: true
extraMounts:
- hostPath: ./examples/kind/egress_selector_configuration.yaml
containerPath: /etc/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml
containerPath: /etc/srv/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml
- role: worker
- role: worker
EOF
Expand All @@ -149,6 +149,13 @@ jobs:
docker load --input konnectivity-agent.tar
/usr/local/bin/kind load docker-image gcr.io/k8s-staging-kas-network-proxy/proxy-server:master --name ${{ env.KIND_CLUSTER_NAME}}
/usr/local/bin/kind load docker-image gcr.io/k8s-staging-kas-network-proxy/proxy-agent:master --name ${{ env.KIND_CLUSTER_NAME}}

docker exec kind-control-plane mkdir -p /etc/srv/kubernetes/{konnectivity-server,pki}
docker exec kind-control-plane cp -f /etc/kubernetes/pki/apiserver.crt /etc/srv/kubernetes/pki/apiserver.crt
docker exec kind-control-plane cp -f /etc/kubernetes/pki/apiserver.key /etc/srv/kubernetes/pki/apiserver.key
docker exec kind-control-plane cp -f /etc/kubernetes/admin.conf /etc/srv/kubernetes/admin.conf
docker exec kind-control-plane chown -R 1002:1000 /etc/srv/kubernetes

kubectl apply -f examples/kind/konnectivity-server.yaml
kubectl apply -f examples/kind/konnectivity-agent-ds.yaml

Expand Down
11 changes: 11 additions & 0 deletions examples/kind/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,17 @@ Have a nice day! 👋
Once the cluster is ready install the `apiserver-network-proxy` components:

```sh

$ docker exec kind-control-plane mkdir -p /etc/srv/kubernetes/{konnectivity-server,pki}

$ docker exec kind-control-plane cp -f /etc/kubernetes/pki/apiserver.crt /etc/srv/kubernetes/pki/apiserver.crt

$ docker exec kind-control-plane cp -f /etc/kubernetes/pki/apiserver.key /etc/srv/kubernetes/pki/apiserver.key

$ docker exec kind-control-plane cp -f /etc/kubernetes/admin.conf /etc/srv/kubernetes/admin.conf

$ docker exec kind-control-plane chown -R 1002:1000 /etc/srv/kubernetes

$ kubectl apply -f konnectivity-server.yaml
clusterrolebinding.rbac.authorization.k8s.io/system:konnectivity-server created
daemonset.apps/konnectivity-server created
Expand Down
2 changes: 1 addition & 1 deletion examples/kind/egress_selector_configuration.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ egressSelections:
proxyProtocol: GRPC
transport:
uds:
udsName: /etc/kubernetes/konnectivity-server/konnectivity-server.socket
udsName: /etc/srv/kubernetes/konnectivity-server/konnectivity-server.socket
- name: master
connection:
proxyProtocol: Direct
Expand Down
10 changes: 5 additions & 5 deletions examples/kind/kind.config
Original file line number Diff line number Diff line change
Expand Up @@ -18,15 +18,15 @@ nodes:
"egress-selector-config-file": "/etc/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
extraVolumes:
- name: egress-selector-config-file
hostPath: "/etc/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
mountPath: "/etc/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
hostPath: "/etc/srv/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
mountPath: "/etc/srv/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml"
readOnly: true
- name: konnectivity-server
hostPath: "/etc/kubernetes/konnectivity-server"
mountPath: "/etc/kubernetes/konnectivity-server"
hostPath: "/etc/srv/kubernetes/konnectivity-server"
mountPath: "/etc/srv/kubernetes/konnectivity-server"
readOnly: true
extraMounts:
- hostPath: ./egress_selector_configuration.yaml
containerPath: /etc/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml
containerPath: /etc/srv/kubernetes/konnectivity-server-config/egress_selector_configuration.yaml
- role: worker
- role: worker
33 changes: 22 additions & 11 deletions examples/kind/konnectivity-server.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,9 @@ spec:
nodeSelector:
node-role.kubernetes.io/control-plane: ""
hostNetwork: true
securityContext:
runAsUser: 1002
runAsGroup: 1000
containers:
- name: konnectivity-server-container
image: gcr.io/k8s-staging-kas-network-proxy/proxy-server:master
Expand All @@ -64,9 +67,9 @@ spec:
"--log-file=/var/log/konnectivity-server.log",
"--logtostderr=true",
"--log-file-max-size=0",
"--uds-name=/etc/kubernetes/konnectivity-server/konnectivity-server.socket",
"--cluster-cert=/etc/kubernetes/pki/apiserver.crt",
"--cluster-key=/etc/kubernetes/pki/apiserver.key",
"--uds-name=/etc/srv/kubernetes/konnectivity-server/konnectivity-server.socket",
"--cluster-cert=/etc/srv/kubernetes/pki/apiserver.crt",
"--cluster-key=/etc/srv/kubernetes/pki/apiserver.key",
"--server-port=0",
"--agent-port=8091",
"--health-port=8092",
Expand All @@ -75,7 +78,7 @@ spec:
"--mode=grpc",
"--agent-namespace=kube-system",
"--agent-service-account=konnectivity-agent",
"--kubeconfig=/etc/kubernetes/admin.conf",
"--kubeconfig=/etc/srv/kubernetes/admin.conf",
"--authentication-audience=system:konnectivity-server",
]
livenessProbe:
Expand Down Expand Up @@ -103,20 +106,28 @@ spec:
- name: varlogkonnectivityserver
mountPath: /var/log/konnectivity-server.log
readOnly: false
- name: kubernetes
mountPath: /etc/kubernetes
readOnly: true
- name: konnectivity-home
mountPath: /etc/kubernetes/konnectivity-server
mountPath: /etc/srv/kubernetes/konnectivity-server
- name: pki
mountPath: /etc/srv/kubernetes/pki
readOnly: true
- name: kubeconfig
mountPath: /etc/srv/kubernetes/admin.conf
readOnly: true
volumes:
- name: varlogkonnectivityserver
hostPath:
path: /var/log/konnectivity-server.log
type: FileOrCreate
- name: kubernetes
- name: pki
hostPath:
path: /etc/kubernetes
path: /etc/srv/kubernetes/pki
type: DirectoryOrCreate
- name: kubeconfig
hostPath:
path: /etc/srv/kubernetes/admin.conf
type: FileOrCreate
- name: konnectivity-home
hostPath:
path: /etc/kubernetes/konnectivity-server
path: /etc/srv/kubernetes/konnectivity-server
type: DirectoryOrCreate