Skip to content

Commit

Permalink
Merge pull request #75 from projectsyn/update-helm-chart
Browse files Browse the repository at this point in the history
Update Vault Helm chart to 0.27.0
  • Loading branch information
simu authored Nov 24, 2023
2 parents 172be94 + e1bbf71 commit 538582b
Show file tree
Hide file tree
Showing 15 changed files with 30 additions and 21 deletions.
4 changes: 2 additions & 2 deletions class/defaults.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ parameters:
vault:
=_metadata:
multi_instance: true
kubernetes_version: '1.18'
kubernetes_version: '1.24'
images:
vault:
registry: docker.io
Expand All @@ -15,7 +15,7 @@ parameters:
charts:
vault:
source: https://helm.releases.hashicorp.com
version: 0.19.0
version: 0.27.0
namespace: ${_instance}
name: ${_instance}
ingress:
Expand Down
2 changes: 1 addition & 1 deletion class/vault.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ parameters:
helm_params:
name: ${vault:name}
namespace: ${vault:namespace}
api_versions: networking.k8s.io/v1beta1/Ingress
api_versions: networking.k8s.io/v1/Ingress
kube_version: ${vault:kubernetes_version}
- input_paths:
- ${_base_directory}/component/unseal.jsonnet
Expand Down
7 changes: 5 additions & 2 deletions docs/modules/ROOT/pages/references/parameters.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -23,10 +23,13 @@ The name of the deployed component.
== `kubernetes_version`
[horizontal]
type:: string
default:: `1.18`
default:: `1.24`

The Kubernetes version of the cluster the component is deployed to.
This is relevant for the `Ingress` API version.
This parameter is passed to Helm when rendering the Helm chart.
The default chart version used by the component requires Kubernetes 1.20 or newer.

We recommend setting this parameter based on the cluster's `kubernetesVersion` dynamic fact.

== `images`

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar-server-binding
roleRef:
apiGroup: rbac.authorization.k8s.io
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,6 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar-config
namespace: vault
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar-discovery-role
namespace: vault
rules:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar-discovery-rolebinding
namespace: vault
roleRef:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
apiVersion: policy/v1beta1
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
labels:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar
namespace: vault
spec:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
vault-active: 'true'
name: foobar-active
namespace: vault
spec:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar-standby
namespace: vault
spec:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
vault-internal: 'true'
name: foobar-internal
namespace: vault
spec:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
apiVersion: networking.k8s.io/v1beta1
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
annotations:
Expand All @@ -8,7 +8,7 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar
namespace: vault
spec:
Expand All @@ -17,9 +17,12 @@ spec:
http:
paths:
- backend:
serviceName: foobar-active
servicePort: 8200
service:
name: foobar-active
port:
number: 8200
path: /
pathType: Prefix
tls:
- hosts:
- vault.todo.tld
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar
namespace: vault
spec:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,6 @@ metadata:
app.kubernetes.io/instance: foobar
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: vault
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
name: foobar
namespace: vault
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ spec:
app.kubernetes.io/instance: foobar
app.kubernetes.io/name: vault
component: server
helm.sh/chart: vault-0.19.0
helm.sh/chart: vault-0.27.0
spec:
affinity:
podAntiAffinity:
Expand Down Expand Up @@ -151,6 +151,7 @@ spec:
limits:
cpu: 100m
memory: 64Mi
hostNetwork: false
securityContext:
fsGroup: 1000
runAsGroup: 1000
Expand Down

0 comments on commit 538582b

Please sign in to comment.