From c5350f524d47054cf360d8c0136e38afffd94d4a Mon Sep 17 00:00:00 2001 From: Simon Lundkvist Date: Tue, 19 Nov 2024 13:01:19 +0100 Subject: [PATCH] apps sc: upgrade opensearch to v2.17.1 --- config/schemas/config.yaml | 4 +- .../opensearch/securityadmin/values.yaml | 2 +- helmfile.d/upstream/index.yaml | 4 +- .../opensearch-dashboards/CHANGELOG.md | 94 +++++++- .../opensearch-dashboards/Chart.yaml | 4 +- .../opensearch-dashboards/README.md | 192 ++++++++++------- .../templates/deployment.yaml | 2 +- .../templates/extraManifests.yaml | 4 +- .../templates/service.yaml | 3 + .../templates/serviceMonitor.yaml | 20 ++ .../opensearch-dashboards/values.yaml | 21 ++ .../opensearch/CHANGELOG.md | 110 +++++++++- .../opensearch-project/opensearch/Chart.yaml | 4 +- .../opensearch-project/opensearch/README.md | 203 +++++++++--------- .../opensearch/templates/extraManifests.yaml | 4 +- .../opensearch/templates/service.yaml | 3 + .../opensearch/templates/serviceMonitor.yaml | 20 ++ .../opensearch/templates/statefulset.yaml | 9 +- .../opensearch-project/opensearch/values.yaml | 21 ++ .../values/opensearch/dashboards.yaml.gotmpl | 3 - .../opensearch/securityadmin.yaml.gotmpl | 2 + migration/v0.43/README.md | 180 ++++++++++++++++ migration/v0.43/apply/00-template.sh | 75 +++++++ .../v0.43/apply/20-upgrade-opensearch.sh | 159 ++++++++++++++ migration/v0.43/apply/80-apply.sh | 57 +++++ migration/v0.43/prepare/00-template.sh | 31 +++ migration/v0.43/prepare/50-init.sh | 16 ++ 27 files changed, 1045 insertions(+), 202 deletions(-) create mode 100644 helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/serviceMonitor.yaml create mode 100644 helmfile.d/upstream/opensearch-project/opensearch/templates/serviceMonitor.yaml create mode 100644 migration/v0.43/README.md create mode 100755 migration/v0.43/apply/00-template.sh create mode 100755 migration/v0.43/apply/20-upgrade-opensearch.sh create mode 100755 migration/v0.43/apply/80-apply.sh create mode 100755 migration/v0.43/prepare/00-template.sh create mode 100755 migration/v0.43/prepare/50-init.sh diff --git a/config/schemas/config.yaml b/config/schemas/config.yaml index c831e15e2..1e7b190b9 100644 --- a/config/schemas/config.yaml +++ b/config/schemas/config.yaml @@ -6683,9 +6683,9 @@ properties: type: boolean default: true tektonPipelines: - title: Network Policies Tekton Piepline + title: Network Policies Tekton Pipeline description: |- - Enable network policies for tekton and the peipline. + Enable network policies for tekton and the pipeline. type: object additionalProperties: false properties: diff --git a/helmfile.d/charts/opensearch/securityadmin/values.yaml b/helmfile.d/charts/opensearch/securityadmin/values.yaml index 64d97b759..6ee74d19c 100644 --- a/helmfile.d/charts/opensearch/securityadmin/values.yaml +++ b/helmfile.d/charts/opensearch/securityadmin/values.yaml @@ -5,7 +5,7 @@ imagePullSecrets: [] image: repository: opensearchproject/opensearch pullPolicy: IfNotPresent - tag: 2.15.0 + tag: 2.17.1 helm: hook: post-install,post-upgrade diff --git a/helmfile.d/upstream/index.yaml b/helmfile.d/upstream/index.yaml index 859deb642..3dba214fd 100644 --- a/helmfile.d/upstream/index.yaml +++ b/helmfile.d/upstream/index.yaml @@ -62,8 +62,8 @@ charts: open-policy-agent-gatekeeper/gatekeeper: 3.15.1 - opensearch-project/opensearch: 2.21.0 - opensearch-project/opensearch-dashboards: 2.19.0 + opensearch-project/opensearch: 2.26.1 + opensearch-project/opensearch-dashboards: 2.24.1 projectcalico/tigera-operator: v3.26.4 diff --git a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/CHANGELOG.md b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/CHANGELOG.md index 7240ae9d8..639d47751 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/CHANGELOG.md +++ b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/CHANGELOG.md @@ -1,4 +1,5 @@ # Changelog + All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), @@ -13,6 +14,87 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Fixed ### Security --- +## [2.24.1] +### Added +### Changed +### Deprecated +### Removed +### Fixed +- Resolved `helm lint` errors with extraObjects +### Security +--- +## [2.24.0] +### Added +- Updated OpenSearch Dashboards appVersion to 2.17.1 +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.23.0] +### Added +- Updated OpenSearch Dashboards appVersion to 2.17.0 +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.22.0] +### Added +- Ability to add additional `labels` to `serviceMonitor` +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.21.2] +### Added +### Changed +### Deprecated +### Removed +### Fixed +- Bug `protocol` missing for metrics in `Service` +### Security +--- +## [2.21.1] +### Added +### Changed +### Deprecated +### Removed +### Fixed +- Fixed `ServiceMonitor` bug for `port` value +### Security +--- +## [2.21.0] +### Added +- Added `ServiceMonitor` support for Prometheus monitoring +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.20.0] +### Added +- Updated OpenSearch Dashboards appVersion to 2.16.0 +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.19.1] +### Added +### Changed +### Deprecated +### Removed +### Fixed +- Fixed pod topology spread constraints in Dashboards +### Security +--- ## [2.19.0] ### Added - Updated OpenSearch Dashboards appVersion to 2.15.0 @@ -103,7 +185,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Removed ### Fixed ### Security - --- ## [2.11.1] ### Added @@ -340,7 +421,16 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Fixed ### Security -[Unreleased]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.19.0...HEAD +[Unreleased]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.24.1...HEAD +[2.24.1]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.24.0...opensearch-dashboards-2.24.1 +[2.24.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.23.0...opensearch-dashboards-2.24.0 +[2.23.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.22.0...opensearch-dashboards-2.23.0 +[2.22.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.21.1...opensearch-dashboards-2.22.0 +[2.21.2]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.21.1...opensearch-dashboards-2.21.2 +[2.21.1]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.21.0...opensearch-dashboards-2.21.1 +[2.21.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.20.0...opensearch-dashboards-2.21.0 +[2.20.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.19.1...opensearch-dashboards-2.20.0 +[2.19.1]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.19.0...opensearch-dashboards-2.19.1 [2.19.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.18.0...opensearch-dashboards-2.19.0 [2.18.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.17.0...opensearch-dashboards-2.18.0 [2.17.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-dashboards-2.16.0...opensearch-dashboards-2.17.0 diff --git a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/Chart.yaml b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/Chart.yaml index a2d3e7017..ea49bbf78 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/Chart.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/Chart.yaml @@ -1,5 +1,5 @@ apiVersion: v2 -appVersion: 2.15.0 +appVersion: 2.17.1 description: A Helm chart for OpenSearch Dashboards maintainers: - name: DandyDeveloper @@ -9,4 +9,4 @@ maintainers: - name: TheAlgo name: opensearch-dashboards type: application -version: 2.19.0 +version: 2.24.1 diff --git a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/README.md b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/README.md index ed0b0740a..57def7f0b 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/README.md +++ b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/README.md @@ -2,99 +2,139 @@ This Helm chart installs [OpenSearch Dashboards](https://github.com/opensearch-project/OpenSearch-Dashboards) with configurable TLS, RBAC and much more configurations. This chart caters to a number of different use cases and setups. - - [Requirements](#requirements) - - [Installing](#installing) - - [Uninstalling](#uninstalling) +- [Requirements](#requirements) +- [Installing](#installing) +- [Uninstalling](#uninstalling) - ## Requirements +## Requirements - * Kubernetes >= 1.14 - * Helm >= 2.17.0 - * We recommend you to have 8 GiB of memory available for this deployment, or at least 4 GiB for the minimum requirement. Else, the deployment is expected to fail. +- Kubernetes >= 1.14 +- Helm >= 2.17.0 +- We recommend you to have 8 GiB of memory available for this deployment, or at least 4 GiB for the minimum requirement. Else, the deployment is expected to fail. - ## Installing +## Installing - Once you've added this Helm repository as per the repository-level [README](../../README.md#installing) - then you can install the chart as follows: +Once you've added this Helm repository as per the repository-level [README](../../README.md#installing) +then you can install the chart as follows: - ```shell - helm install my-release opensearch/opensearch-dashboards - ``` +```shell +helm install my-release opensearch/opensearch-dashboards +``` - The command deploys OpenSearch Dashboards with its associated components on the Kubernetes cluster in the default configuration. +The command deploys OpenSearch Dashboards with its associated components on the Kubernetes cluster in the default configuration. - **NOTE:** If using Helm 2 then you'll need to add the [`--name`](https://v2.helm.sh/docs/helm/#options-21) command line argument. If unspecified, Helm 2 will autogenerate a name for you. +**NOTE:** If using Helm 2 then you'll need to add the [`--name`](https://v2.helm.sh/docs/helm/#options-21) command line argument. If unspecified, Helm 2 will autogenerate a name for you. - ## Uninstalling - To delete/uninstall the chart with the release name `my-release`: +## Uninstalling - ```shell - helm uninstall my-release - ``` +To delete/uninstall the chart with the release name `my-release`: + +```shell +helm uninstall my-release +``` ## Configuration -| Parameter | Description | Default | -|------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------| -| `envFrom` | Templatable string to be passed to the [environment from variables][] which will be appended to the `envFrom:` definition for the container | `[]` | -| `config` | Allows you to add any config files in `/usr/share/opensearch-dashboards/` such as `opensearch_dashboards.yml`. String or map format may be used for specifying content of each configuration file. In case of string format, the whole content of the config file will be replaced by new config file value when in case of using map format content of configuration file will be a result of merge. In both cases content passed through tpl. See [values.yaml][] for an example of the formatting | `{}` | -| `extraContainers` | Array of extra containers | `""` | -| `extraEnvs` | Extra environments variables to be passed to OpenSearch services | `[]` | -| `extraInitContainers` | Array of extra init containers | `[]` | -| `extraVolumeMounts` | Array of extra volume mounts | `[] ` | -| `extraVolumes` | Array of extra volumes to be added | `[]` | -| `fullnameOverride` | Overrides the `clusterName` and `nodeGroup` when used in the naming of resources. This should only be used when using a single `nodeGroup`, otherwise you will have name conflicts | `""` | -| `hostAliases` | Configurable [hostAliases][] | `[]` | -| `image.pullPolicy` | The Kubernetes [imagePullPolicy][] value | `IfNotPresent` | -| `imagePullSecrets` | Configuration for [imagePullSecrets][] so that you can use a private registry for your image | `[]` | -| `image.tag` | The OpenSearch Docker image tag | `1.0.0` | -| `image.repository` | The OpenSearch Docker image | `opensearchproject/opensearch` | -| `ingress` | Configurable [ingress][] to expose the OpenSearch service. See [values.yaml][] for an example | see [values.yaml][] | -| `labels` | Configurable [labels][] applied to all OpenSearch pods | `{}` | -| `lifecycle` | Allows you to add [lifecycle hooks](https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/). See [values.yaml][] for an example | `{}` | -| `nameOverride` | Overrides the `clusterName` when used in the naming of resources | `""` | -| `nodeSelector` | Configurable [nodeSelector][] so that you can target specific nodes for your OpenSearch cluster | `{}` | -| `podAnnotations` | Configurable [annotations][] applied to all OpenSearch pods | `{}` | -| `podSecurityContext` | Allows you to set the [securityContext][] for the pod | see [values.yaml][] | -| `priorityClassName` | The name of the [PriorityClass][]. No default is supplied as the PriorityClass must be created first | `""` | -| `rbac` | Configuration for creating a role, role binding and ServiceAccount as part of this Helm chart with `create: true`. Also can be used to reference an external ServiceAccount with `serviceAccountName: "externalServiceAccountName"` | see [values.yaml][] | -| `resources` | Allows you to set the [resources][] for the StatefulSet | see [values.yaml][] | -| `secretMounts` | Allows you easily mount a secret as a file inside the StatefulSet. Useful for mounting certificates and other secrets. See [values.yaml][] for an example | `[]` | -| `securityContext` | Allows you to set the [securityContext][] for the container | see [values.yaml][] | -| `service.annotations` | [LoadBalancer annotations][] that Kubernetes will use for the service. This will configure load balancer if `service.type` is `LoadBalancer` | `{}` | -| `service.headless.annotations` | Allow you to set annotations on the headless service | `{}` | -| `service.externalTrafficPolicy` | Some cloud providers allow you to specify the [LoadBalancer externalTrafficPolicy][]. Kubernetes will use this to preserve the client source IP. This will configure load balancer if `service.type` is `LoadBalancer` | `""` | -| `service.httpPortName` | The name of the http port within the service | `http` | -| `service.labelsHeadless` | Labels to be added to headless service | `{}` | -| `service.labels` | Labels to be added to non-headless service | `{}` | -| `service.loadBalancerIP` | Some cloud providers allow you to specify the [loadBalancer][] IP. If the `loadBalancerIP` field is not specified, the IP is dynamically assigned. If you specify a `loadBalancerIP` but your cloud provider does not support the feature, it is ignored. | `""` | -| `service.loadBalancerSourceRanges` | The IP ranges that are allowed to access | `[]` | -| `service.nodePort` | Custom [nodePort][] port that can be set if you are using `service.type: nodePort` | `""` | -| `service.transportPortName` | The name of the transport port within the service | `transport` | -| `service.type` | OpenSearch [Service Types][] | `ClusterIP` | -| `service.ipFamilyPolicy` | This sets the preferred ip addresses in case of a dual-stack server, there are three options [PreferDualStack, SingleStack, RequireDualStack], [more information on dual stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/) | `""` | -| `service.ipFamilies` | Sets the preferred IP variants and in which order they are preferred, the first family you list is used for the legacy .spec.ClusterIP field, [more information on dual stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/) | `""` | -| `tolerations` | Configurable [tolerations][] | `[]` | +| Parameter | Description | Default | +| :--- | :--- | :--- | +| `envFrom` | Templatable string to be passed to the [environment from variables][] which will be appended to the `envFrom:` definition for the container | `[]` | +| `config` | Allows you to add any config files in `/usr/share/opensearch-dashboards/` such as `opensearch_dashboards.yml`. String or map format may be used for specifying content of each configuration file. In case of string format, the whole content of the config file will be replaced by new config file value when in case of using map format content of configuration file will be a result of merge. In both cases content passed through tpl. See [values.yaml][] for an example of the formatting | `{}` | +| `extraContainers` | Array of extra containers | `""` | +| `extraEnvs` | Extra environments variables to be passed to OpenSearch services | `[]` | +| `extraInitContainers` | Array of extra init containers | `[]` | +| `extraVolumeMounts` | Array of extra volume mounts | `[]` | +| `extraVolumes` | Array of extra volumes to be added | `[]` | +| `fullnameOverride` | Overrides the `clusterName` and `nodeGroup` when used in the naming of resources. This should only be used when using a single `nodeGroup`, otherwise you will have name conflicts | `""` | +| `hostAliases` | Configurable [hostAliases][] | `[]` | +| `image.pullPolicy` | The Kubernetes [imagePullPolicy][] value | `IfNotPresent` | +| `imagePullSecrets` | Configuration for [imagePullSecrets][] so that you can use a private registry for your image | `[]` | +| `image.tag` | The OpenSearch Docker image tag | `1.0.0` | +| `image.repository` | The OpenSearch Docker image | `opensearchproject/opensearch` | +| `ingress` | Configurable [ingress][] to expose the OpenSearch service. See [values.yaml][] for an example | see [values.yaml][] | +| `labels` | Configurable [labels][] applied to all OpenSearch pods | `{}` | +| `lifecycle` | Allows you to add [lifecycle hooks](https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/). See [values.yaml][] for an example | `{}` | +| `nameOverride` | Overrides the `clusterName` when used in the naming of resources | `""` | +| `nodeSelector` | Configurable [nodeSelector][] so that you can target specific nodes for your OpenSearch cluster | `{}` | +| `podAnnotations` | Configurable [annotations][] applied to all OpenSearch pods | `{}` | +| `podSecurityContext` | Allows you to set the [securityContext][] for the pod | see [values.yaml][] | +| `priorityClassName` | The name of the [PriorityClass][]. No default is supplied as the PriorityClass must be created first | `""` | +| `rbac` | Configuration for creating a role, role binding and ServiceAccount as part of this Helm chart with `create: true`. Also can be used to reference an external ServiceAccount with `serviceAccountName: "externalServiceAccountName"` | see [values.yaml][] | +| `resources` | Allows you to set the [resources][] for the StatefulSet | see [values.yaml][] | +| `secretMounts` | Allows you easily mount a secret as a file inside the StatefulSet. Useful for mounting certificates and other secrets. See [values.yaml][] for an example | `[]` | +| `securityContext` | Allows you to set the [securityContext][] for the container | see [values.yaml][] | +| `service.annotations` | [LoadBalancer annotations][] that Kubernetes will use for the service. This will configure load balancer if `service.type` is `LoadBalancer` | `{}` | +| `service.headless.annotations` | Allow you to set annotations on the headless service | `{}` | +| `service.externalTrafficPolicy` | Some cloud providers allow you to specify the [LoadBalancer externalTrafficPolicy][]. Kubernetes will use this to preserve the client source IP. This will configure load balancer if `service.type` is `LoadBalancer` | `""` | +| `service.httpPortName` | The name of the http port within the service | `http` | +| `service.labelsHeadless` | Labels to be added to headless service | `{}` | +| `service.labels` | Labels to be added to non-headless service | `{}` | +| `service.loadBalancerIP` | Some cloud providers allow you to specify the [loadBalancer][] IP. If the `loadBalancerIP` field is not specified, the IP is dynamically assigned. If you specify a `loadBalancerIP` but your cloud provider does not support the feature, it is ignored. | `""` | +| `service.loadBalancerSourceRanges` | The IP ranges that are allowed to access | `[]` | +| `service.nodePort` | Custom [nodePort][] port that can be set if you are using `service.type: nodePort` | `""` | +| `service.transportPortName` | The name of the transport port within the service | `transport` | +| `service.type` | OpenSearch [Service Types][] | `ClusterIP` | +| `service.ipFamilyPolicy` | This sets the preferred ip addresses in case of a dual-stack server, there are three options [PreferDualStack, SingleStack, RequireDualStack], [more information on dual stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/) | `""` | +| `service.ipFamilies` | Sets the preferred IP variants and in which order they are preferred, the first family you list is used for the legacy .spec.ClusterIP field, [more information on dual stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/) | `""` | +| `service.metricsPort` | The metrics port (for Performance Analyzer) that Kubernetes will use for the service. | `9601` | +| `service.metricsPortName` | The name of the metrics port (for Performance Analyzer) within the service | `metrics` | +| `tolerations` | Configurable [tolerations][] | `[]` | | `topologySpreadConstraints` | Configuration for pod [topologySpreadConstraints][] | `[]` | -| `updateStrategy` | The [updateStrategy][] for the StatefulSet. By default Kubernetes will wait for the cluster to be green after upgrading each pod. Setting this to `OnDelete` will allow you to manually delete each pod during upgrades | `RollingUpdate` | -| `extraObjects` | Array of extra K8s manifests to deploy | list `[]` | -| `autoscaling.enabled` | Prerequisite: Install/Configure metrics server, to install use `kubectl apply -f https://github.com/kubernetes-sigs/metrics-server/releases/latest/download/components.yaml`, See https://github.com/kubernetes-sigs/metrics-server. | false | -| `autoscaling.minReplicas` | The lower limit for the number of replicas to which the autoscaler can scale down. | 1 | -| `autoscaling.maxReplicas` | The upper limit for the number of replicas to which the autoscaler can scale up. | 10 | -| `autoscaling.targetCPU` | The target value of the average CPU across all OpenSearch Dashboards pods. | 80 | -| `autoscaling.targetMemory` | The target value of the average memory across all OpenSearch Dashboards pods. Value should be tuned based on the requested memory value for OpenSearch Dashboards pods. Scaling based on memory utilization may be necessary for large datasets or complex dashboards. | 80 | -| `livenessProbe` | Configuration fields for the liveness [probe][] | see [exampleLiveness][] in `values.yaml`| -| `readinessProbe` | Configuration fields for the readiness [probe][] | see [exampleReadiness][] in `values.yaml`| -| `startupProbe` | Configuration fields for the startup [probe][] | see [exampleStartup][] in `values.yaml` | -| `plugins.enabled` | Allow/disallow to add 3rd Party / Custom plugins not offered in the default OpenSearchDashboards image | false | -| `plugins.installList` | Array containing the Opensearch Dashboards plugins to be installed in container | [] | -| `opensearchDashboardsYml.defaultMode` | Allow you to set the defaultMode for the opensearch_dashboards.yml mounted as configMap | | -| `dashboardAnnotations` | Allows you to configure custom annotation in the deployement of the OpenSearchDashboards container | {} | +| `updateStrategy` | The [updateStrategy][] for the StatefulSet. By default Kubernetes will wait for the cluster to be green after upgrading each pod. Setting this to `OnDelete` will allow you to manually delete each pod during upgrades | `RollingUpdate` | +| `extraObjects` | Array of extra K8s manifests to deploy | list `[]` | +| `autoscaling.enabled` | Prerequisite: Install/Configure metrics server, to install use `kubectl apply -f https://github.com/kubernetes-sigs/metrics-server/releases/latest/download/components.yaml`, See [Metrics Server](https://github.com/kubernetes-sigs/metrics-server). | false | +| `autoscaling.minReplicas` | The lower limit for the number of replicas to which the autoscaler can scale down. | 1 | +| `autoscaling.maxReplicas` | The upper limit for the number of replicas to which the autoscaler can scale up. | 10 | +| `autoscaling.targetCPU` | The target value of the average CPU across all OpenSearch Dashboards pods. | 80 | +| `autoscaling.targetMemory` | The target value of the average memory across all OpenSearch Dashboards pods. Value should be tuned based on the requested memory value for OpenSearch Dashboards pods. Scaling based on memory utilization may be necessary for large datasets or complex dashboards. | 80 | +| `livenessProbe` | Configuration fields for the liveness [probe][] | see [exampleLiveness][] in `values.yaml`| +| `readinessProbe` | Configuration fields for the readiness [probe][] | see [exampleReadiness][] in `values.yaml`| +| `startupProbe` | Configuration fields for the startup [probe][] | see [exampleStartup][] in `values.yaml` | +| `plugins.enabled` | Allow/disallow to add 3rd Party / Custom plugins not offered in the default OpenSearchDashboards image | false | +| `plugins.installList` | Array containing the Opensearch Dashboards plugins to be installed in container | [] | +| `opensearchDashboardsYml.defaultMode` | Allow you to set the defaultMode for the opensearch_dashboards.yml mounted as configMap | | +| `dashboardAnnotations` | Allows you to configure custom annotation in the deployement of the OpenSearchDashboards container | {} | +| `serviceMonitor.enabled` | Enables the creation of a [ServiceMonitor] resource for Prometheus monitoring. Requires the Prometheus Operator to be installed in your Kubernetes cluster. | `false` | +| `serviceMonitor.path` | Path where metrics are exposed. Applicable only if `serviceMonitor.enabled` is set to `true`. | `/_prometheus/metrics` | +| `serviceMonitor.interval` | Interval at which metrics should be scraped by Prometheus. Applicable only if `serviceMonitor.enabled` is set to `true`. | `10s` | -[probe]: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes +[environment from variables]: https://kubernetes.io/docs/tasks/configure-pod-container/configure-pod-configmap/#configure-all-key-value-pairs-in-a-configmap-as-container-environment-variables + +[values.yaml]:https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch/values.yaml + +[hostAliases]: https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ + +[imagepullPolicy]: https://kubernetes.io/docs/concepts/containers/images/#updating-images +[imagePullSecrets]: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ +[ingress]: https://kubernetes.io/docs/concepts/services-networking/ingress/ +[resources]: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/ + +[labels]: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ + +[nodeSelector]: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector + +[annotations]: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ + +[securityContext]: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ +[priorityClass]: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/#priorityclass + +[loadBalancer annotations]: https://kubernetes.io/docs/concepts/services-networking/service/#ssl-support-on-aws +[loadBalancer externalTrafficPolicy]: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip +[loadBalancer]: https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer + +[nodePort]: https://kubernetes.io/docs/concepts/services-networking/service/#nodeport + +[tolerations]: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ + +[updateStrategy]: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/ + +[service types]: https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types + +[probe]: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes [exampleStartup]: https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch-dashboards/values.yaml#17 [exampleLiveness]: https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch-dashboards/values.yaml#27 [exampleReadiness]: https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch-dashboards/values.yaml#37 [topologySpreadConstraints]: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints + +[ServiceMonitor]: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#servicemonitor diff --git a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/deployment.yaml b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/deployment.yaml index f1d4916ab..256cf054d 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/deployment.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/deployment.yaml @@ -79,7 +79,7 @@ spec: {{- end }} {{- if .Values.topologySpreadConstraints }} topologySpreadConstraints: -{- toYaml .Values.topologySpreadConstraints | nindent 8 }} +{{- toYaml .Values.topologySpreadConstraints | nindent 8 }} {{- end }} {{- if .Values.imagePullSecrets }} imagePullSecrets: diff --git a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/extraManifests.yaml b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/extraManifests.yaml index d6abe5fbf..c169b9d0b 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/extraManifests.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/extraManifests.yaml @@ -1,8 +1,8 @@ {{ range .Values.extraObjects }} --- {{- if typeIs "string" . }} -{{- tpl . $ }} +{{ tpl . $ }} {{- else }} -{{- tpl (toYaml .) $ }} +{{ tpl (toYaml .) $ }} {{- end }} {{ end }} \ No newline at end of file diff --git a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/service.yaml b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/service.yaml index e520f5c17..16962f167 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/service.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/service.yaml @@ -36,6 +36,9 @@ spec: protocol: TCP name: {{ .Values.service.httpPortName | default "http" }} targetPort: {{ .Values.service.port }} + - name: {{ .Values.service.metricsPortName | default "metrics" }} + protocol: TCP + port: {{ .Values.service.metricsPort }} selector: app: {{ .Chart.Name }} release: {{ .Release.Name | quote }} diff --git a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/serviceMonitor.yaml b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/serviceMonitor.yaml new file mode 100644 index 000000000..ae92805a4 --- /dev/null +++ b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/templates/serviceMonitor.yaml @@ -0,0 +1,20 @@ +{{- if .Values.serviceMonitor.enabled }} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: {{ template "opensearch-dashboards.fullname" . }}-service-monitor + namespace: {{ .Release.Namespace }} + labels: + {{- include "opensearch-dashboards.labels" . | nindent 4 }} + {{- with .Values.serviceMonitor.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: + {{- include "opensearch-dashboards.selectorLabels" . | nindent 6 }} + endpoints: + - port: {{ .Values.service.metricsPortName | default "metrics" }} + interval: {{ .Values.serviceMonitor.interval }} + path: {{ .Values.serviceMonitor.path }} +{{- end }} diff --git a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/values.yaml b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/values.yaml index 40fece824..d461a6e2b 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch-dashboards/values.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch-dashboards/values.yaml @@ -156,6 +156,7 @@ service: # ipFamilies: # - IPv4 port: 5601 + metricsPort: 9601 loadBalancerIP: "" nodePort: "" labels: {} @@ -163,6 +164,7 @@ service: loadBalancerSourceRanges: [] # 0.0.0.0/0 httpPortName: http + metricsPortName: metrics ingress: enabled: false @@ -276,3 +278,22 @@ plugins: enabled: false installList: [] # - example-fake-plugin-downloadable-url + +# ServiceMonitor Configuration for Prometheus +# Enabling this option will create a ServiceMonitor resource that allows Prometheus to scrape metrics from the OpenSearch service. +serviceMonitor: + # Set to true to enable the ServiceMonitor resource for OpenSearch Dashboards + enabled: false + + # HTTP path where metrics are exposed by OpenSearch Dashboards. + # Ensure this path is correctly set in your service. + path: /_prometheus/metrics + + # Frequency at which Prometheus will scrape metrics. + # Modify as needed for your monitoring requirements. + interval: 10s + + # additional labels to be added to the ServiceMonitor + # labels: + # k8s.example.com/prometheus: kube-prometheus + labels: {} diff --git a/helmfile.d/upstream/opensearch-project/opensearch/CHANGELOG.md b/helmfile.d/upstream/opensearch-project/opensearch/CHANGELOG.md index d206b2ed4..986909463 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch/CHANGELOG.md +++ b/helmfile.d/upstream/opensearch-project/opensearch/CHANGELOG.md @@ -1,4 +1,5 @@ # Changelog + All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), @@ -13,6 +14,97 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Fixed ### Security --- +## [2.26.1] +### Added +### Changed +### Deprecated +### Removed +### Fixed +- Resolved `helm lint` errors with extraObjects +### Security +--- +## [2.26.0] +### Added +- Updated OpenSearch appVersion to 2.17.1 +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.25.0] +### Added +- Updated OpenSearch appVersion to 2.17.0 +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.24.1] +### Added +- Allow user-defined labels on persistent volume claim +### Changed +### Deprecated +### Removed +### Fixed +### Security +======= +## [2.24.0] +### Added +- Ability to add additional `labels` to `serviceMonitor` +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.23.2] +### Added +- Metrics configuration in both `Service` templates +### Changed +### Deprecated +### Removed +### Fixed +- Bug `protocol` missing for metrics in `Service` +### Security +--- +## [2.23.1] +### Added +### Changed +### Deprecated +### Removed +### Fixed +- Fixed `ServiceMonitor` bug for `port` value +### Security +--- +## [2.23.0] +### Added +- Added `ServiceMonitor` support for Prometheus monitoring +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- +## [2.22.1] +### Added +### Changed +### Deprecated +### Removed +### Fixed +- Fixed opensearchJavaOpts defaults in README +### Security +--- +## [2.22.0] +### Added +- Updated OpenSearch appVersion to 2.16.0 +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- ## [2.21.0] ### Added - Updated OpenSearch appVersion to 2.15.0 @@ -43,8 +135,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [2.18.0] ### Added ### Breaking - - Requires an initial admin password to be setup starting from App Version OpenSearch 2.12.0. Refer this github issue: https://github.com/opensearch-project/security/issues/3622 - - Updated OpenSearch appVersion to 2.12.0 +- Requires an initial admin password to be setup starting from App Version OpenSearch 2.12.0. Refer this github issue: https://github.com/opensearch-project/security/issues/3622 +- Updated OpenSearch appVersion to 2.12.0 ### Changed ### Deprecated ### Removed @@ -420,8 +512,17 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Fixed ### Security - -[Unreleased]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.21.0...HEAD +[Unreleased]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.26.1...HEAD +[2.26.1]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.26.0...opensearch-2.26.1 +[2.26.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.25.0...opensearch-2.26.0 +[2.25.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.24.1...opensearch-2.25.0 +[2.24.1]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.24.0...opensearch-2.24.1 +[2.24.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.23.1...opensearch-2.24.0 +[2.23.2]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.23.1...opensearch-2.23.2 +[2.23.1]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.23.0...opensearch-2.23.1 +[2.23.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.22.1...opensearch-2.23.0 +[2.22.1]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.22.0...opensearch-2.22.1 +[2.22.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.21.0...opensearch-2.22.0 [2.21.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.20.0...opensearch-2.21.0 [2.20.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.19.0...opensearch-2.20.0 [2.19.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.18.0...opensearch-2.19.0 @@ -464,4 +565,3 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 [2.2.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.1.0...opensearch-2.2.0 [2.1.0]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.0.1...opensearch-2.1.0 [2.0.1]: https://github.com/opensearch-project/helm-charts/compare/opensearch-2.0.0...opensearch-2.0.1 - diff --git a/helmfile.d/upstream/opensearch-project/opensearch/Chart.yaml b/helmfile.d/upstream/opensearch-project/opensearch/Chart.yaml index ba8b87f0f..fdbc5dce8 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch/Chart.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch/Chart.yaml @@ -1,5 +1,5 @@ apiVersion: v2 -appVersion: 2.15.0 +appVersion: 2.17.1 description: A Helm chart for OpenSearch home: https://opensearch.org maintainers: @@ -13,4 +13,4 @@ sources: - https://github.com/opensearch-project/opensearch - https://github.com/opensearch-project/helm-charts type: application -version: 2.21.0 +version: 2.26.1 diff --git a/helmfile.d/upstream/opensearch-project/opensearch/README.md b/helmfile.d/upstream/opensearch-project/opensearch/README.md index 7991d37ad..d68f28d35 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch/README.md +++ b/helmfile.d/upstream/opensearch-project/opensearch/README.md @@ -3,16 +3,16 @@ This Helm chart installs [OpenSearch](https://github.com/opensearch-project/OpenSearch) with configurable TLS, RBAC and much more configurations. This chart caters a number of different use cases and setups. - [OpenSearch Helm Chart](#opensearch-helm-chart) - - [Requirements](#requirements) - - [Installing](#installing) - - [Uninstalling](#uninstalling) - - [Configuration](#configuration) +- [Requirements](#requirements) +- [Installing](#installing) +- [Uninstalling](#uninstalling) +- [Configuration](#configuration) ## Requirements -* Kubernetes >= 1.14 -* Helm >= 2.17.0 -* We recommend you to have 8 GiB of memory available for this deployment, or at least 4 GiB for the minimum requirement. Else, the deployment is expected to fail. +- Kubernetes >= 1.14 +- Helm >= 2.17.0 +- We recommend you to have 8 GiB of memory available for this deployment, or at least 4 GiB for the minimum requirement. Else, the deployment is expected to fail. ## Installing @@ -27,6 +27,7 @@ The command deploys OpenSearch with its associated components (data statefulsets **NOTE:** If using Helm 2 then you'll need to add the [`--name`](https://v2.helm.sh/docs/helm/#options-21) command line argument. If unspecified, Helm 2 will autogenerate a name for you. ## Uninstalling + To delete/uninstall the chart with the release name `my-release`: ```shell @@ -35,95 +36,98 @@ helm uninstall my-release ## Configuration -| Parameter | Description | Default | -| ----------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | -| `antiAffinityTopologyKey` | The [anti-affinity][] topology key. By default this will prevent multiple Opensearch nodes from running on the same Kubernetes node | `kubernetes.io/hostname` | -| `antiAffinity` | Setting this to `hard` enforces the [anti-affinity][] rules. If it is set to `soft` it will be done "best effort". Setting it to `custom` will use whatever is set in the `customAntiAffinity` parameter. Other values will be ignored. | `hard` | -| `clusterName` | This will be used as the OpenSearch cluster name and should be unique per cluster in the namespace | `opensearch-cluster` | -| `customAntiAffinity` | Allows passing in custom anti-affinity settings as defined in the [anti-affinity][] rules. Using this parameter requires setting the `antiAffinity` parameter to `custom`. | `{}` | -| `enableServiceLinks` | Set to false to disabling service links, which can cause slow pod startup times when there are many services in the current namespace. | `true` | -| `envFrom` | Templatable string to be passed to the [environment from variables][] which will be appended to the `envFrom:` definition for the container | `[]` | -| `config` | Allows you to add any config files in `/usr/share/opensearch/config/` such as `opensearch.yml` and `log4j2.properties`. String or map format may be used for specifying content of each configuration file. In case of string format, the whole content of the config file will be replaced by new config file value when in case of using map format content of configuration file will be a result of merge. In both cases content passed through tpl. See [values.yaml][] for an example of the formatting (passed through tpl) | `{}` | -| `opensearchJavaOpts` | Java options for OpenSearch. This is where you should configure the jvm heap size | `-Xmx1g -Xms1g` | -| `majorVersion` | Used to set major version specific configuration. If you are using a custom image and not running the default OpenSearch version you will need to set this to the version you are running (e.g. `majorVersion: 1`) | `""` | -| `global.dockerRegistry` | Set if you want to change the default docker registry, e.g. a private one. | `""` | -| `extraContainers` | Array of extra containers | `""` | -| `extraEnvs` | Extra environments variables to be passed to OpenSearch services | `[]` | -| `extraInitContainers` | Array of extra init containers | `[]` | -| `extraVolumeMounts` | Array of extra volume mounts | `[]` | -| `extraVolumes` | Array of extra volumes to be added | `[]` | -| `fullnameOverride` | Overrides the `clusterName` and `nodeGroup` when used in the naming of resources. This should only be used when using a single `nodeGroup`, otherwise you will have name conflicts | `""` | -| `hostAliases` | Configurable [hostAliases][] | `[]` | -| `httpHostPort` | Expose another http-port as hostPort. Refer to documentation for more information and requirements about using hostPorts. | `""` | -| `httpPort` | The http port that Kubernetes will use for the healthchecks and the service. If you change this you will also need to set `http.port` in `extraEnvs` | `9200` | -| `image.pullPolicy` | The Kubernetes [imagePullPolicy][] value | `IfNotPresent` | -| `imagePullSecrets` | Configuration for [imagePullSecrets][] so that you can use a private registry for your image | `[]` | -| `image.tag` | The OpenSearch Docker image tag | `1.0.0` | -| `image.repository` | The OpenSearch Docker image | `opensearchproject/opensearch` | -| `ingress` | Configurable [ingress][] to expose the OpenSearch service. See [values.yaml][] for an example | see [values.yaml][] | -| `initResources` | Allows you to set the [resources][] for the `initContainer` in the StatefulSet | `{}` | -| `keystore` | Allows you map Kubernetes secrets into the keystore. | `[]` | -| `labels` | Configurable [labels][] applied to all OpenSearch pods | `{}` | -| `masterService` | The service name used to connect to the masters. You only need to set this if your master `nodeGroup` is set to something other than `master` | `""` | -| `maxUnavailable` | The [maxUnavailable][] value for the pod disruption budget. By default this will prevent Kubernetes from having more than 1 unhealthy pod in the node group | `1` | -| `metricsPort` | The metrics port (for Performance Analyzer) that Kubernetes will use for the service. | `9600` | -| `nameOverride` | Overrides the `clusterName` when used in the naming of resources | `""` | -| `networkHost` | Value for the `network.host OpenSearch setting` | `0.0.0.0` | -| `networkPolicy.create` | Enable network policy creation for OpenSearch | `false` | -| `nodeAffinity` | Value for the [node affinity settings][] | `{}` | -| `nodeGroup` | This is the name that will be used for each group of nodes in the cluster. The name will be `clusterName-nodeGroup-X` , `nameOverride-nodeGroup-X` if a `nameOverride` is specified, and `fullnameOverride-X` if a `fullnameOverride` is specified | `master` | -| `nodeSelector` | Configurable [nodeSelector][] so that you can target specific nodes for your OpenSearch cluster | `{}` | -| `persistence` | Enables a persistent volume for OpenSearch data. | see [values.yaml][] | -| `persistence.enableInitChown` | Disable the `fsgroup-volume` initContainer that will update permissions on the persistent disk. | `true` | -| `podAffinity` | Value for the [pod affinity settings][] | `{}` | -| `podAnnotations` | Configurable [annotations][] applied to all OpenSearch pods | `{}` | -| `podManagementPolicy` | By default Kubernetes [deploys StatefulSets serially][]. This deploys them in parallel so that they can discover each other | `Parallel` | -| `podSecurityContext` | Allows you to set the [securityContext][] for the pod | see [values.yaml][] | -| `podSecurityPolicy` | Configuration for create a pod security policy with minimal permissions to run this Helm chart with `create: true`. Also can be used to reference an external pod security policy with `name: "externalPodSecurityPolicy"` | see [values.yaml][] | -| `priorityClassName` | The name of the [PriorityClass][]. No default is supplied as the PriorityClass must be created first | `""` | -| `rbac` | Configuration for creating a role, role binding and ServiceAccount as part of this Helm chart with `create: true`. Also can be used to reference an external ServiceAccount with `serviceAccountName: "externalServiceAccountName"` | see [values.yaml][] | -| `rbac.automountServiceAccountToken` | Controls whether a service account token should be automatically mounted to the Pods. | `true` | -| `replicas` | Kubernetes replica count for the StatefulSet (i.e. how many pods) | `3` | -| `resources` | Allows you to set the [resources][] for the StatefulSet | see [values.yaml][] | -| `roles` | A list of the specific node [roles][] for the `nodeGroup` | see [values.yaml][] | -| `singleNode` | If `discovery.type` in the opensearch configuration is set to `"single-node"`, this should be set to `true`. If `true`, replicas will be forced to `1`. | `false` | -| `schedulerName` | Name of the [alternate scheduler][] | `""` | -| `secretMounts` | Allows you easily mount a secret as a file inside the StatefulSet. Useful for mounting certificates and other secrets. See [values.yaml][] for an example | `[]` | -| `securityConfig` | Configure the opensearch security plugin. There are multiple ways to inject configuration into the chart, see [values.yaml][] details. | By default an insecure demonstration configuration is set. This **must** be changed before going to production. | -| `securityContext` | Allows you to set the [securityContext][] for the container | see [values.yaml][] | -| `service.annotations` | [LoadBalancer annotations][] that Kubernetes will use for the service. This will configure load balancer if `service.type` is `LoadBalancer` | `{}` | -| `service.headless.annotations` | Allow you to set annotations on the headless service | `{}` | -| `service.externalTrafficPolicy` | Some cloud providers allow you to specify the [LoadBalancer externalTrafficPolicy][]. Kubernetes will use this to preserve the client source IP. This will configure load balancer if `service.type` is `LoadBalancer` | `""` | -| `service.httpPortName` | The name of the http port within the service | `http` | -| `service.labelsHeadless` | Labels to be added to headless service | `{}` | -| `service.labels` | Labels to be added to non-headless service | `{}` | -| `service.loadBalancerIP` | Some cloud providers allow you to specify the [loadBalancer][] IP. If the `loadBalancerIP` field is not specified, the IP is dynamically assigned. If you specify a `loadBalancerIP` but your cloud provider does not support the feature, it is ignored. | `""` | -| `service.loadBalancerSourceRanges` | The IP ranges that are allowed to access | `[]` | -| `service.metricsPortName` | The name of the metrics port (for Performance Analyzer) within the service | `metrics` | -| `service.nodePort` | Custom [nodePort][] port that can be set if you are using `service.type: nodePort` | `""` | -| `service.transportPortName` | The name of the transport port within the service | `transport` | -| `service.type` | OpenSearch [Service Types][] | `ClusterIP` | -| `service.ipFamilyPolicy` | This sets the preferred ip addresses in case of a dual-stack server, there are three options [PreferDualStack, SingleStack, RequireDualStack], [more information on dual stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/) | `""` | -| `service.ipFamilies` | Sets the preferred IP variants and in which order they are preferred, the first family you list is used for the legacy .spec.ClusterIP field, [more information on dual stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/) | `""` | -| `sidecarResources` | Allows you to set the [resources][] for the sidecar containers in the StatefulSet | {} | -| `sysctlInit` | Allows you to enable the `sysctlInit` to set sysctl vm.max_map_count through privileged `initContainer`. | `enabled: false` | -| `sysctlVmMaxMapCount` | Sets the [vm.max_map_count][] needed for OpenSearch | `262144` | -| `terminationGracePeriod` | The [terminationGracePeriod][] in seconds used when trying to stop the pod | `120` | -| `tolerations` | Configurable [tolerations][] | `[]` | -| `topologySpreadConstraints` | Configuration for pod [topologySpreadConstraints][] | `[]` | -| `transportHostPort` | Expose another transport port as hostPort. Refer to documentation for more information and requirements about using hostPorts. | `""` | -| `transportPort` | The transport port that Kubernetes will use for the service. If you change this you will also need to set transport port configuration in `extraEnvs` | `9300` | -| `updateStrategy` | The [updateStrategy][] for the StatefulSet. By default Kubernetes will wait for the cluster to be green after upgrading each pod. Setting this to `OnDelete` will allow you to manually delete each pod during upgrades | `RollingUpdate` | -| `volumeClaimTemplate` | Configuration for the [volumeClaimTemplate for StatefulSets][]. You will want to adjust the storage (default `30Gi` ) and the `storageClassName` if you are using a different storage class | see [values.yaml][] | -| `extraObjects` | Array of extra K8s manifests to deploy | list `[]` | -| `livenessProbe` | Configuration fields for the liveness [probe][] | see [exampleLiveness][] in `values.yaml` | -| `readinessProbe` | Configuration fields for the readiness [probe][] | see [exampleReadiness][] in `values.yaml` | -| `startupProbe` | Configuration fields for the startup [probe][] | see [exampleStartup][] in `values.yaml` | -| `plugins.enabled` | Allow/disallow to add 3rd Party / Custom plugins not offered in the default OpenSearchDashboards image | false | -| `plugins.installList` | Array containing the Opensearch Dashboards plugins to be installed in container | \[] | -| `opensearchLifecycle` | Allows you to configure lifecycle hooks for the OpenSearch container in the StatefulSet | {} | -| `lifecycle` | Allows you to configure lifecycle hooks for the OpenSearch container in the StatefulSet | {} | -| `openSearchAnnotations` | Allows you to configure custom annotation in the StatefullSet of the OpenSearch container | {} | +| Parameter | Description | Default | +| :--- | :--- | :--- | +| `antiAffinityTopologyKey` | The [anti-affinity][] topology key. By default this will prevent multiple Opensearch nodes from running on the same Kubernetes node | `kubernetes.io/hostname` | +| `antiAffinity` | Setting this to `hard` enforces the [anti-affinity][] rules. If it is set to `soft` it will be done "best effort". Setting it to `custom` will use whatever is set in the `customAntiAffinity` parameter. Other values will be ignored. | `hard` | +| `clusterName` | This will be used as the OpenSearch cluster name and should be unique per cluster in the namespace | `opensearch-cluster` | +| `customAntiAffinity` | Allows passing in custom anti-affinity settings as defined in the [anti-affinity][] rules. Using this parameter requires setting the `antiAffinity` parameter to `custom`. | `{}` | +| `enableServiceLinks` | Set to false to disabling service links, which can cause slow pod startup times when there are many services in the current namespace. | `true` | +| `envFrom` | Templatable string to be passed to the [environment from variables][] which will be appended to the `envFrom:` definition for the container | `[]` | +| `config` | Allows you to add any config files in `/usr/share/opensearch/config/` such as `opensearch.yml` and `log4j2.properties`. String or map format may be used for specifying content of each configuration file. In case of string format, the whole content of the config file will be replaced by new config file value when in case of using map format content of configuration file will be a result of merge. In both cases content passed through tpl. See [values.yaml][] for an example of the formatting (passed through tpl) | `{}` | +| `opensearchJavaOpts` | Java options for OpenSearch. This is where you should configure the jvm heap size | `-Xmx512M -Xms512M` | +| `majorVersion` | Used to set major version specific configuration. If you are using a custom image and not running the default OpenSearch version you will need to set this to the version you are running (e.g. `majorVersion: 1`) | `""` | +| `global.dockerRegistry` | Set if you want to change the default docker registry, e.g. a private one. | `""` | +| `extraContainers` | Array of extra containers | `""` | +| `extraEnvs` | Extra environments variables to be passed to OpenSearch services | `[]` | +| `extraInitContainers` | Array of extra init containers | `[]` | +| `extraVolumeMounts` | Array of extra volume mounts | `[]` | +| `extraVolumes` | Array of extra volumes to be added | `[]` | +| `fullnameOverride` | Overrides the `clusterName` and `nodeGroup` when used in the naming of resources. This should only be used when using a single `nodeGroup`, otherwise you will have name conflicts | `""` | +| `hostAliases` | Configurable [hostAliases][] | `[]` | +| `httpHostPort` | Expose another http-port as hostPort. Refer to documentation for more information and requirements about using hostPorts. | `""` | +| `httpPort` | The http port that Kubernetes will use for the healthchecks and the service. If you change this you will also need to set `http.port` in `extraEnvs` | `9200` | +| `image.pullPolicy` | The Kubernetes [imagePullPolicy][] value | `IfNotPresent` | +| `imagePullSecrets` | Configuration for [imagePullSecrets][] so that you can use a private registry for your image | `[]` | +| `image.tag` | The OpenSearch Docker image tag | `1.0.0` | +| `image.repository` | The OpenSearch Docker image | `opensearchproject/opensearch` | +| `ingress` | Configurable [ingress][] to expose the OpenSearch service. See [values.yaml][] for an example | see [values.yaml][] | +| `initResources` | Allows you to set the [resources][] for the `initContainer` in the StatefulSet | `{}` | +| `keystore` | Allows you map Kubernetes secrets into the keystore. | `[]` | +| `labels` | Configurable [labels][] applied to all OpenSearch pods | `{}` | +| `masterService` | The service name used to connect to the masters. You only need to set this if your master `nodeGroup` is set to something other than `master` | `""` | +| `maxUnavailable` | The [maxUnavailable][] value for the pod disruption budget. By default this will prevent Kubernetes from having more than 1 unhealthy pod in the node group | `1` | +| `metricsPort` | The metrics port (for Performance Analyzer) that Kubernetes will use for the service. | `9600` | +| `nameOverride` | Overrides the `clusterName` when used in the naming of resources | `""` | +| `networkHost` | Value for the `network.host OpenSearch setting` | `0.0.0.0` | +| `networkPolicy.create` | Enable network policy creation for OpenSearch | `false` | +| `nodeAffinity` | Value for the [node affinity settings][] | `{}` | +| `nodeGroup` | This is the name that will be used for each group of nodes in the cluster. The name will be `clusterName-nodeGroup-X` , `nameOverride-nodeGroup-X` if a `nameOverride` is specified, and `fullnameOverride-X` if a `fullnameOverride` is specified | `master` | +| `nodeSelector` | Configurable [nodeSelector][] so that you can target specific nodes for your OpenSearch cluster | `{}` | +| `persistence` | Enables a persistent volume for OpenSearch data. | see [values.yaml][] | +| `persistence.enableInitChown` | Disable the `fsgroup-volume` initContainer that will update permissions on the persistent disk. | `true` | +| `podAffinity` | Value for the [pod affinity settings][] | `{}` | +| `podAnnotations` | Configurable [annotations][] applied to all OpenSearch pods | `{}` | +| `podManagementPolicy` | By default Kubernetes [deploys StatefulSets serially][]. This deploys them in parallel so that they can discover each other | `Parallel` | +| `podSecurityContext` | Allows you to set the [securityContext][] for the pod | see [values.yaml][] | +| `podSecurityPolicy` | Configuration for create a pod security policy with minimal permissions to run this Helm chart with `create: true`. Also can be used to reference an external pod security policy with `name: "externalPodSecurityPolicy"` | see [values.yaml][] | +| `priorityClassName` | The name of the [PriorityClass][]. No default is supplied as the PriorityClass must be created first | `""` | +| `rbac` | Configuration for creating a role, role binding and ServiceAccount as part of this Helm chart with `create: true`. Also can be used to reference an external ServiceAccount with `serviceAccountName: "externalServiceAccountName"` | see [values.yaml][] | +| `rbac.automountServiceAccountToken` | Controls whether a service account token should be automatically mounted to the Pods. | `true` | +| `replicas` | Kubernetes replica count for the StatefulSet (i.e. how many pods) | `3` | +| `resources` | Allows you to set the [resources][] for the StatefulSet | see [values.yaml][] | +| `roles` | A list of the specific node [roles][] for the `nodeGroup` | see [values.yaml][] | +| `singleNode` | If `discovery.type` in the opensearch configuration is set to `"single-node"`, this should be set to `true`. If `true`, replicas will be forced to `1`. | `false` | +| `schedulerName` | Name of the [alternate scheduler][] | `""` | +| `secretMounts` | Allows you easily mount a secret as a file inside the StatefulSet. Useful for mounting certificates and other secrets. See [values.yaml][] for an example | `[]` | +| `securityConfig` | Configure the opensearch security plugin. There are multiple ways to inject configuration into the chart, see [values.yaml][] details. | By default an insecure demonstration configuration is set. This **must** be changed before going to production. | +| `securityContext` | Allows you to set the [securityContext][] for the container | see [values.yaml][] | +| `service.annotations` | [LoadBalancer annotations][] that Kubernetes will use for the service. This will configure load balancer if `service.type` is `LoadBalancer` | `{}` | +| `service.headless.annotations` | Allow you to set annotations on the headless service | `{}` | +| `service.externalTrafficPolicy` | Some cloud providers allow you to specify the [LoadBalancer externalTrafficPolicy][]. Kubernetes will use this to preserve the client source IP. This will configure load balancer if `service.type` is `LoadBalancer` | `""` | +| `service.httpPortName` | The name of the http port within the service | `http` | +| `service.labelsHeadless` | Labels to be added to headless service | `{}` | +| `service.labels` | Labels to be added to non-headless service | `{}` | +| `service.loadBalancerIP` | Some cloud providers allow you to specify the [loadBalancer][] IP. If the `loadBalancerIP` field is not specified, the IP is dynamically assigned. If you specify a `loadBalancerIP` but your cloud provider does not support the feature, it is ignored. | `""` | +| `service.loadBalancerSourceRanges` | The IP ranges that are allowed to access | `[]` | +| `service.metricsPortName` | The name of the metrics port (for Performance Analyzer) within the service | `metrics` | +| `service.nodePort` | Custom [nodePort][] port that can be set if you are using `service.type: nodePort` | `""` | +| `service.transportPortName` | The name of the transport port within the service | `transport` | +| `service.type` | OpenSearch [Service Types][] | `ClusterIP` | +| `service.ipFamilyPolicy` | This sets the preferred ip addresses in case of a dual-stack server, there are three options [PreferDualStack, SingleStack, RequireDualStack], [more information on dual stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/) | `""` | +| `service.ipFamilies` | Sets the preferred IP variants and in which order they are preferred, the first family you list is used for the legacy .spec.ClusterIP field, [more information on dual stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/) | `""` | +| `sidecarResources` | Allows you to set the [resources][] for the sidecar containers in the StatefulSet | {} | +| `sysctlInit` | Allows you to enable the `sysctlInit` to set sysctl vm.max_map_count through privileged `initContainer`. | `enabled: false` | +| `sysctlVmMaxMapCount` | Sets the [vm.max_map_count][] needed for OpenSearch | `262144` | +| `terminationGracePeriod` | The [terminationGracePeriod][] in seconds used when trying to stop the pod | `120` | +| `tolerations` | Configurable [tolerations][] | `[]` | +| `topologySpreadConstraints` | Configuration for pod [topologySpreadConstraints][] | `[]` | +| `transportHostPort` | Expose another transport port as hostPort. Refer to documentation for more information and requirements about using hostPorts. | `""` | +| `transportPort` | The transport port that Kubernetes will use for the service. If you change this you will also need to set transport port configuration in `extraEnvs` | `9300` | +| `updateStrategy` | The [updateStrategy][] for the StatefulSet. By default Kubernetes will wait for the cluster to be green after upgrading each pod. Setting this to `OnDelete` will allow you to manually delete each pod during upgrades | `RollingUpdate` | +| `volumeClaimTemplate` | Configuration for the [volumeClaimTemplate for StatefulSets][]. You will want to adjust the storage (default `30Gi` ) and the `storageClassName` if you are using a different storage class | see [values.yaml][] | +| `extraObjects` | Array of extra K8s manifests to deploy | list `[]` | +| `livenessProbe` | Configuration fields for the liveness [probe][] | see [exampleLiveness][] in `values.yaml` | +| `readinessProbe` | Configuration fields for the readiness [probe][] | see [exampleReadiness][] in `values.yaml` | +| `startupProbe` | Configuration fields for the startup [probe][] | see [exampleStartup][] in `values.yaml` | +| `plugins.enabled` | Allow/disallow to add 3rd Party / Custom plugins not offered in the default OpenSearchDashboards image | false | +| `plugins.installList` | Array containing the Opensearch Dashboards plugins to be installed in container | \[] | +| `opensearchLifecycle` | Allows you to configure lifecycle hooks for the OpenSearch container in the StatefulSet | {} | +| `lifecycle` | Allows you to configure lifecycle hooks for the OpenSearch container in the StatefulSet | {} | +| `openSearchAnnotations` | Allows you to configure custom annotation in the StatefullSet of the OpenSearch container | {} | +| `serviceMonitor.enabled` | Enables the creation of a [ServiceMonitor] resource for Prometheus monitoring. Requires the Prometheus Operator to be installed in your Kubernetes cluster. | `false` | +| `serviceMonitor.path` | Path where metrics are exposed. Applicable only if `serviceMonitor.enabled` is set to `true`. | `/_prometheus/metrics` | +| `serviceMonitor.interval` | Interval at which metrics should be scraped by Prometheus. Applicable only if `serviceMonitor.enabled` is set to `true`. | `10s` | [anti-affinity]: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity @@ -133,7 +137,7 @@ helm uninstall my-release [hostAliases]: https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ -[image.pullPolicy]: https://kubernetes.io/docs/concepts/containers/images/#updating-images +[imagepullPolicy]: https://kubernetes.io/docs/concepts/containers/images/#updating-images [imagePullSecrets]: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ [ingress]: https://kubernetes.io/docs/concepts/services-networking/ingress/ [resources]: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/ @@ -163,12 +167,9 @@ helm uninstall my-release [loadBalancer annotations]: https://kubernetes.io/docs/concepts/services-networking/service/#ssl-support-on-aws [loadBalancer externalTrafficPolicy]: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip [loadBalancer]: https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer -[maxUnavailable]: https://kubernetes.io/docs/tasks/run-application/configure-pdb/#specifying-a-poddisruptionbudget [nodePort]: https://kubernetes.io/docs/concepts/services-networking/service/#nodeport -[nodeSelector]: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector - [vm.max_map_count]: https://opensearch.org/docs/opensearch/install/important-settings/ [terminationGracePeriod]: https://kubernetes.io/docs/concepts/workloads/pods/pod/#termination-of-pods @@ -186,3 +187,5 @@ helm uninstall my-release [exampleStartup]: https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch/values.yaml#332 [exampleLiveness]: https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch/values.yaml#340 [exampleReadiness]: https://github.com/opensearch-project/helm-charts/blob/main/charts/opensearch/values.yaml#349 + +[ServiceMonitor]: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#servicemonitor diff --git a/helmfile.d/upstream/opensearch-project/opensearch/templates/extraManifests.yaml b/helmfile.d/upstream/opensearch-project/opensearch/templates/extraManifests.yaml index d6abe5fbf..c169b9d0b 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch/templates/extraManifests.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch/templates/extraManifests.yaml @@ -1,8 +1,8 @@ {{ range .Values.extraObjects }} --- {{- if typeIs "string" . }} -{{- tpl . $ }} +{{ tpl . $ }} {{- else }} -{{- tpl (toYaml .) $ }} +{{ tpl (toYaml .) $ }} {{- end }} {{ end }} \ No newline at end of file diff --git a/helmfile.d/upstream/opensearch-project/opensearch/templates/service.yaml b/helmfile.d/upstream/opensearch-project/opensearch/templates/service.yaml index 4c28b2f3e..78a6b0742 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch/templates/service.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch/templates/service.yaml @@ -32,6 +32,9 @@ spec: - name: {{ .Values.service.transportPortName | default "transport" }} protocol: TCP port: {{ .Values.transportPort }} + - name: {{ .Values.service.metricsPortName | default "metrics" }} + protocol: TCP + port: {{ .Values.metricsPort }} {{- if .Values.service.loadBalancerIP }} loadBalancerIP: {{ .Values.service.loadBalancerIP }} {{- end }} diff --git a/helmfile.d/upstream/opensearch-project/opensearch/templates/serviceMonitor.yaml b/helmfile.d/upstream/opensearch-project/opensearch/templates/serviceMonitor.yaml new file mode 100644 index 000000000..79837932c --- /dev/null +++ b/helmfile.d/upstream/opensearch-project/opensearch/templates/serviceMonitor.yaml @@ -0,0 +1,20 @@ +{{- if .Values.serviceMonitor.enabled }} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: {{ template "opensearch.uname" . }}-service-monitor + namespace: {{ .Release.Namespace }} + labels: + {{- include "opensearch.labels" . | nindent 4 }} + {{- with .Values.serviceMonitor.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: + {{- include "opensearch.selectorLabels" . | nindent 6 }} + endpoints: + - port: {{ .Values.service.metricsPortName | default "metrics" }} + interval: {{ .Values.serviceMonitor.interval }} + path: {{ .Values.serviceMonitor.path }} +{{- end }} diff --git a/helmfile.d/upstream/opensearch-project/opensearch/templates/statefulset.yaml b/helmfile.d/upstream/opensearch-project/opensearch/templates/statefulset.yaml index 72e149765..3ce437fca 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch/templates/statefulset.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch/templates/statefulset.yaml @@ -27,9 +27,14 @@ spec: volumeClaimTemplates: - metadata: name: {{ template "opensearch.uname" . }} - {{- if .Values.persistence.labels.enabled }} + {{- if or .Values.persistence.labels.enabled .Values.persistence.labels.additionalLabels }} labels: - {{- include "opensearch.labels" . | nindent 8 }} + {{- if .Values.persistence.labels.enabled }} + {{- include "opensearch.labels" . | nindent 8 }} + {{- end }} + {{- with .Values.persistence.labels.additionalLabels }} + {{- toYaml . | nindent 8 }} + {{- end }} {{- end }} {{- with .Values.persistence.annotations }} annotations: diff --git a/helmfile.d/upstream/opensearch-project/opensearch/values.yaml b/helmfile.d/upstream/opensearch-project/opensearch/values.yaml index 33737661c..02e356f43 100644 --- a/helmfile.d/upstream/opensearch-project/opensearch/values.yaml +++ b/helmfile.d/upstream/opensearch-project/opensearch/values.yaml @@ -205,6 +205,8 @@ persistence: labels: # Add default labels for the volumeClaimTemplate of the StatefulSet enabled: false + # Add custom labels for the volumeClaimTemplate of the StatefulSet + additionalLabels: {} # OpenSearch Persistent Volume Storage Class # If defined, storageClassName: # If set to "-", storageClassName: "", which disables dynamic provisioning @@ -529,3 +531,22 @@ extraObjects: [] # selector: # matchLabels: # {{- include "opensearch.selectorLabels" . | nindent 6 }} + +# ServiceMonitor Configuration for Prometheus +# Enabling this option will create a ServiceMonitor resource that allows Prometheus to scrape metrics from the OpenSearch service. +serviceMonitor: + # Set to true to enable the ServiceMonitor resource + enabled: false + + # HTTP path where metrics are exposed. + # Ensure this matches your OpenSearch service configuration. + path: /_prometheus/metrics + + # Frequency at which Prometheus will scrape metrics. + # Adjust based on your needs. + interval: 10s + + # additional labels to be added to the ServiceMonitor + # labels: + # k8s.example.com/prometheus: kube-prometheus + labels: {} diff --git a/helmfile.d/values/opensearch/dashboards.yaml.gotmpl b/helmfile.d/values/opensearch/dashboards.yaml.gotmpl index 47be3d0a1..39c2815a3 100644 --- a/helmfile.d/values/opensearch/dashboards.yaml.gotmpl +++ b/helmfile.d/values/opensearch/dashboards.yaml.gotmpl @@ -12,9 +12,6 @@ config: - Authorization - securitytenant - opensearchDashboards: - index: .opensearch_dashboards - opensearch_security: {{ if .Values.opensearch.sso.enabled }} auth: diff --git a/helmfile.d/values/opensearch/securityadmin.yaml.gotmpl b/helmfile.d/values/opensearch/securityadmin.yaml.gotmpl index 589d7303f..250f8dc80 100644 --- a/helmfile.d/values/opensearch/securityadmin.yaml.gotmpl +++ b/helmfile.d/values/opensearch/securityadmin.yaml.gotmpl @@ -9,6 +9,8 @@ securityConfig: config: dynamic: + kibana: + server_username: dashboards authc: basic_internal_auth_domain: description: "Authenticate via HTTP Basic against internal users database" diff --git a/migration/v0.43/README.md b/migration/v0.43/README.md new file mode 100644 index 000000000..83dde1a56 --- /dev/null +++ b/migration/v0.43/README.md @@ -0,0 +1,180 @@ +# Upgrade to v0.43.x + +> [!WARNING] +> Upgrade only supported from v0.42.x. + + + +## Prerequisites + +- [ ] Read through the changelog to check if there are any changes you need to be aware of. Read through the release notes, Platform Administrator notices, Application Developer notices, and Security notice. +- [ ] Notify the users (if any) before the upgrade starts; +- [ ] Check if there are any pending changes to the environment; +- [ ] Check the state of the environment, pods, nodes and backup jobs: + + ```bash + ./bin/ck8s test sc|wc + ./bin/ck8s ops kubectl sc|wc get pods -A -o custom-columns=NAMESPACE:metadata.namespace,POD:metadata.name,READY-false:status.containerStatuses[*].ready,REASON:status.containerStatuses[*].state.terminated.reason | grep false | grep -v Completed + ./bin/ck8s ops kubectl sc|wc get nodes + ./bin/ck8s ops kubectl sc|wc get jobs -A + ./bin/ck8s ops helm sc|wc list -A --all + velero get backup + ``` + +- [ ] Silence the notifications for the alerts. e.g you can use [alertmanager silences](https://prometheus.io/docs/alerting/latest/alertmanager/#silences); + +## Automatic method + +1. Pull the latest changes and switch to the correct branch: + + ```bash + git pull + git switch -d v0.43.x + ``` + +1. Prepare upgrade - *non-disruptive* + + > *Done before maintenance window.* + + ```bash + ./bin/ck8s upgrade both v0.43 prepare + + # check if the netpol IPs need to be updated + ./bin/ck8s update-ips both dry-run + # if you agree with the changes apply + ./bin/ck8s update-ips both apply + ``` + + > **Note:** + > It is possible to upgrade `wc` and `sc` clusters separately by replacing `both` when running the `upgrade` command, e.g. the following will only upgrade the workload cluster: + + ```bash + ./bin/ck8s upgrade wc v0.43 prepare + ./bin/ck8s upgrade wc v0.43 apply + ``` + +1. If Tekton is enabled, ensure to add appropriate network policies that allow traffic from Tekton to OpenSearch. + + To check if the tekton is enabled, run the following command + + ``` + yq4 '.tektonPipelines.enabled == true' $CK8S_CONFIG_PATH/sc-config.yaml + ``` + + Example of how the network policies for the pipeline can be found on the [documentation page](https://elastisys.io/welkin/operator-manual/schema/config-properties-network-policies-config-properties-network-policies-tekton-pipeline/#pipeline). + +1. Apply upgrade - *disruptive* + + > *Done during maintenance window.* + + ```bash + ./bin/ck8s upgrade both v0.43 apply + ``` + +## Manual method + +### Prepare upgrade - *non-disruptive* + +> *Done before maintenance window.* + +1. Pull the latest changes and switch to the correct branch: + + ```bash + git pull + git switch -d v0.43.x + ``` + +1. Set whether or not upgrade should be prepared for `both` clusters or for one of `sc` or `wc`: + + ```bash + export CK8S_CLUSTER= + ``` + +1. Update apps configuration: + + This will take a backup into `backups/` before modifying any files. + + ```bash + ./bin/ck8s init ${CK8S_CLUSTER} + # or + ./migration/v0.43/prepare/50-init.sh + + # check if the netpol IPs need to be updated + ./bin/ck8s update-ips ${CK8S_CLUSTER} dry-run + # if you agree with the changes apply + ./bin/ck8s update-ips ${CK8S_CLUSTER} apply + ``` + +### Apply upgrade - *disruptive* + +> *Done during maintenance window.* + +1. Set whether or not upgrade should be applied for `both` clusters or for one of `sc` or `wc`: + + ```bash + export CK8S_CLUSTER= + ``` + +1. Upgrade Opensearch: + + ```bash + ./migration/v0.43/apply/20-upgrade-opensearch.sh execute + ``` + +1. Upgrade applications: + + ```bash + ./bin/ck8s apply {sc|wc} + # or + ./migration/v0.43/apply/80-apply.sh execute + ``` + +## Postrequisite: + +- [ ] Check the state of the environment, pods and nodes: + + ```bash + ./bin/ck8s test sc|wc + ./bin/ck8s ops kubectl sc|wc get pods -A -o custom-columns=NAMESPACE:metadata.namespace,POD:metadata.name,READY-false:status.containerStatuses[*].ready,REASON:status.containerStatuses[*].state.terminated.reason | grep false | grep -v Completed + ./bin/ck8s ops kubectl sc|wc get nodes + ./bin/ck8s ops helm sc|wc list -A --all + ``` + +- [ ] Enable the notifications for the alerts; +- [ ] Notify the users (if any) when the upgrade is complete; + +> [!NOTE] +> Additionally it is good to check: +> +> - if any alerts generated by the upgrade didn't close; +> - if you can login to Grafana, Opensearch or Harbor; +> - you can see fresh metrics and logs. diff --git a/migration/v0.43/apply/00-template.sh b/migration/v0.43/apply/00-template.sh new file mode 100755 index 000000000..648db7ac8 --- /dev/null +++ b/migration/v0.43/apply/00-template.sh @@ -0,0 +1,75 @@ +#!/usr/bin/env bash + +ROOT="$(readlink -f "$(dirname "${0}")/../../../")" + +# shellcheck source=scripts/migration/lib.sh +source "${ROOT}/scripts/migration/lib.sh" + +# functions currently available in the library: +# - logging: +# - log_info(_no_newline) +# - log_warn(_no_newline) +# - log_error(_no_newline) +# - log_fatal # this will call "exit 1" +# +# - kubectl +# # Use kubectl with kubeconfig set +# - kubectl_do +# # Perform kubectl delete, will not cause errors if the resource is missing +# - kubectl_delete +# +# - helm +# # Use helm with kubeconfig set +# - helm_do +# # Checks if a release is installed +# - helm_installed +# # Uninstalls a release if it is installed +# - helm_uninstall +# +# - helmfile +# # Use helmfile with kubeconfig set +# - helmfile_do +# # For selector args all will be prefixed with "-l" +# # List releases matching the selector +# - helmfile_list +# # Apply releases matching the selector +# - helmfile_apply +# # Check for changes on releases matching the selector +# - helmfile_change +# # Destroy releases matching the selector +# - helmfile_destroy +# # Replaces the releases matching the selector, performing destroy and apply on each release individually +# - helmfile_replace +# # Upgrades the releases matching the selector, performing automatic rollback on failure set "CK8S_ROLLBACK=false" to disable +# - helmfile_upgrade + +run() { + case "${1:-}" in + execute) + # Note: 00-template.sh will be skipped by the upgrade command + log_info "no operation: this is a template" + + if [[ "${CK8S_CLUSTER}" =~ ^(sc|both)$ ]]; then + log_info "operation on service cluster" + fi + if [[ "${CK8S_CLUSTER}" =~ ^(wc|both)$ ]]; then + log_info "operation on workload cluster" + fi + ;; + rollback) + log_warn "rollback not implemented" + + # if [[ "${CK8S_CLUSTER}" =~ ^(sc|both)$ ]]; then + # log_info "rollback operation on service cluster" + # fi + # if [[ "${CK8S_CLUSTER}" =~ ^(wc|both)$ ]]; then + # log_info "rollback operation on workload cluster" + # fi + ;; + *) + log_fatal "usage: \"${0}\" " + ;; + esac +} + +run "${@}" diff --git a/migration/v0.43/apply/20-upgrade-opensearch.sh b/migration/v0.43/apply/20-upgrade-opensearch.sh new file mode 100755 index 000000000..d2f1dd9f3 --- /dev/null +++ b/migration/v0.43/apply/20-upgrade-opensearch.sh @@ -0,0 +1,159 @@ +#!/usr/bin/env bash + +ROOT="$(readlink -f "$(dirname "${0}")/../../../")" + +# shellcheck source=scripts/migration/lib.sh +source "${ROOT}/scripts/migration/lib.sh" + +clone_opensearch_dashboard_index() { + + log_info "- Cloning index .opensearch_dashboards to .kibana" + log_info "- Getting name of .opensearch_dashboards index" + os_dashboards_index=$(curl -sS -kL -u "${user}:${password}" -X GET "${os_url}"/_alias/.opensearch_dashboards | jq -r 'to_entries | .[0].key') + + if [[ "${os_dashboards_index}" != .opensearch_dashboards* ]]; then + log_fatal "Failed to get index name of the .opensearch_dashboards alias" + fi + + log_info "- Marking index '${os_dashboards_index}' as read-only" + resp=$(curl -sS -kL -u "${user}:${password}" -X PUT "${os_url}"/"${os_dashboards_index}"/_settings -H 'Content-Type: application/json' -d' + { + "settings": { + "index.blocks.write": true + } + } + ') + + acknowledged=$(echo "${resp}" | grep "^{" | jq -r '.acknowledged') + if [ "${acknowledged}" = "true" ]; then + log_info "- Marked '${os_dashboards_index}' as read-only" + else + log_fatal "Failed to mark index '${os_dashboards_index}' as read-only" "${resp}" + fi + + log_info "- Cloning index '${os_dashboards_index}' to index .kibana_1" + resp=$(curl -sS -kL -u "${user}:${password}" -X PUT "${os_url}"/"${os_dashboards_index}"/_clone/.kibana_1) + acknowledged=$(echo "${resp}" | grep "^{" | jq -r '.acknowledged') + if [ "${acknowledged}" = "true" ]; then + log_info "- Successfully cloned '${os_dashboards_index}' to .kibana_1" + else + log_fatal "Failed to clone index '${os_dashboards_index}' to .kibana_1" "${resp}" + fi + +} + +disable_read_only_kibana_index() { + + log_info "- Disabling read-only mode for .kibana_1" + resp=$(curl -sS -kL -u "${user}:${password}" -X PUT "${os_url}"/.kibana_1/_settings -H 'Content-Type: application/json' -d' + { + "settings": { + "index.blocks.write": false + } + } + ') + acknowledged=$(echo "${resp}" | grep "^{" | jq -r '.acknowledged') + if [ "${acknowledged}" = "true" ]; then + log_info "- Successfully disabled read-only mode for .kibana_1" + else + log_fatal "Failed to disable read-only mode for .kibana_1" "${resp}" + fi + +} + +create_kibana_alias() { + + resp=$(curl -sS -kL -u "${user}:${password}" -X GET "${os_url}"/_alias/.kibana) + if [[ $(echo "${resp}" | jq -r 'to_entries | .[0].key') == .kibana* ]]; then + log_info "- Alias .kibana already exists, skipping" + elif [[ $(echo "${resp}" | jq -r '.status') == "404" ]]; then + log_info "- Creating alias .kibana" + resp=$(curl -sS -kL -u "${user}:${password}" -X PUT "${os_url}"/.kibana_1/_aliases/.kibana) + acknowledged=$(echo "${resp}" | grep "^{" | jq -r '.acknowledged') + if [ "${acknowledged}" = "true" ]; then + log_info "- Successfully created alias .kibana" + else + log_fatal "Failed to create alias .kibana" "${resp}" + fi + else + log_fatal "Failed to check if alias .kibana exists" "${resp}" + fi + +} + +delete_opensearch_dashboards_index() { + + os_dashboards_index=$(curl -sS -kL -u "${user}:${password}" -X GET "${os_url}"/_alias/.opensearch_dashboards | jq -r 'to_entries | .[0].key') + if [[ "${os_dashboards_index}" != .opensearch_dashboards* ]]; then + log_info "- Skipping: Alias .opensearch_dashboards doesn't exist" + else + log_info "- Deleting all .opensearch_dashboards* indices" + resp=$(curl -sS -kL -u "${user}:${password}" -X DELETE "${os_url}"/".opensearch_dashboards*") + acknowledged=$(echo "${resp}" | grep "^{" | jq -r '.acknowledged') + if [ "${acknowledged}" = "true" ]; then + log_info "- Successfully deleted all .opensearch_dashboards* indices" + else + log_fatal "Failed to delete all .opensearch_dashboards* indices" "${resp}" + fi + fi + +} + +run() { + case "${1:-}" in + execute) + + if [[ "${CK8S_CLUSTER}" =~ ^(sc|both)$ ]]; then + log_info "operation on service cluster" + + if [[ ! "$(helm_chart_version "sc" opensearch-system opensearch-master)" = "2.26.1" ]]; then + + log_info "- Scaling down opensearch-dashboards to 0 replicas" + kubectl_do sc -n opensearch-system scale deployment opensearch-dashboards --replicas=0 + + user="admin" + password=$(sops --config "${CK8S_CONFIG_PATH}/.sops.yaml" -d "${CK8S_CONFIG_PATH}"/secrets.yaml | yq4 '.opensearch.adminPassword') + os_url=https://opensearch.$(yq4 '.global.opsDomain' "${CK8S_CONFIG_PATH}"/common-config.yaml) + + resp=$(curl -sS -kL -u "${user}:${password}" -X GET "${os_url}"/.kibana_1) + if [[ $(echo "${resp}" | jq -r 'to_entries | .[0].key') == ".kibana_1" ]]; then + + log_info "- Index .kibana_1 already exists, skipping" + + elif [[ $(echo "${resp}" | jq -r '.error.type') == "index_not_found_exception" ]]; then + + clone_opensearch_dashboard_index + + else + + log_fatal "Failed to check if index .kibana_1 already exists" "${resp}" + + fi + + disable_read_only_kibana_index + create_kibana_alias + delete_opensearch_dashboards_index + + log_info "- Removing opensearch-configurer" + helmfile_destroy sc name=opensearch-configurer + log_info "- Upgrading Opensearch" + helmfile_do sc -lapp=opensearch sync + + else + + log_info "- OpenSearch chart version already 2.26.1, executing generic apply" + helmfile_upgrade sc app=opensearch + + fi + fi + ;; + rollback) + log_warn "rollback not applicable" + ;; + *) + log_fatal "usage: \"${0}\" " + ;; + esac +} + +run "${@}" diff --git a/migration/v0.43/apply/80-apply.sh b/migration/v0.43/apply/80-apply.sh new file mode 100755 index 000000000..1e749193d --- /dev/null +++ b/migration/v0.43/apply/80-apply.sh @@ -0,0 +1,57 @@ +#!/usr/bin/env bash + +ROOT="$(readlink -f "$(dirname "${0}")/../../../")" + +# shellcheck source=scripts/migration/lib.sh +source "${ROOT}/scripts/migration/lib.sh" + +# Add selector filters if covered by other snippets. +# Example: "app!=something" +declare -a skipped +skipped=( +) +declare -a skipped_sc +skipped_sc=( + "app!=opensearch" +) +declare -a skipped_wc +skipped_wc=( +) + +run() { + case "${1:-}" in + execute) + local -a filters + local selector + + if [[ "${CK8S_CLUSTER}" =~ ^(sc|both)$ ]]; then + filters=("${skipped[@]}" "${skipped_sc[@]}") + selector="${filters[*]:-"app!=null"}" + helmfile_upgrade sc "${selector// /,}" + fi + + if [[ "${CK8S_CLUSTER}" =~ ^(wc|both)$ ]]; then + filters=("${skipped[@]}" "${skipped_wc[@]}") + selector="${filters[*]:-"app!=null"}" + helmfile_upgrade wc "${selector// /,}" + fi + ;; + + rollback) + log_warn "rollback not implemented" + + # if [[ "${CK8S_CLUSTER}" =~ ^(sc|both)$ ]]; then + # log_info "rollback operation on service cluster" + # fi + # if [[ "${CK8S_CLUSTER}" =~ ^(wc|both)$ ]]; then + # log_info "rollback operation on workload cluster" + # fi + ;; + + *) + log_fatal "usage: \"${0}\" " + ;; + esac +} + +run "${@}" diff --git a/migration/v0.43/prepare/00-template.sh b/migration/v0.43/prepare/00-template.sh new file mode 100755 index 000000000..d7628160c --- /dev/null +++ b/migration/v0.43/prepare/00-template.sh @@ -0,0 +1,31 @@ +#!/usr/bin/env bash + +HERE="$(dirname "$(readlink -f "${0}")")" +ROOT="$(readlink -f "${HERE}/../../../")" + +# shellcheck source=scripts/migration/lib.sh +source "${ROOT}/scripts/migration/lib.sh" + +# functions currently available in the library: +# - logging: +# - log_info(_no_newline) +# - log_warn(_no_newline) +# - log_error(_no_newline) +# - log_fatal # this will call "exit 1" +# +# - yq: +# - yq_null +# - yq_copy +# - yq_move +# - yq_remove +# - yq_add + +# Note: 00-template.sh will be skipped by the upgrade command +log_info "no operation: this is a template" + +if [[ "${CK8S_CLUSTER}" =~ ^(sc|both)$ ]]; then + log_info "operation on service cluster" +fi +if [[ "${CK8S_CLUSTER}" =~ ^(wc|both)$ ]]; then + log_info "operation on workload cluster" +fi diff --git a/migration/v0.43/prepare/50-init.sh b/migration/v0.43/prepare/50-init.sh new file mode 100755 index 000000000..481a9351e --- /dev/null +++ b/migration/v0.43/prepare/50-init.sh @@ -0,0 +1,16 @@ +#!/usr/bin/env bash + +HERE="$(dirname "$(readlink -f "${0}")")" +ROOT="$(readlink -f "${HERE}/../../../")" + +# shellcheck source=scripts/migration/lib.sh +source "${ROOT}/scripts/migration/lib.sh" + +case "${CK8S_CLUSTER}" in + both|sc|wc) + "${ROOT}/bin/ck8s" init "${CK8S_CLUSTER}" + ;; + *) + log_fatal "usage: 50-init.sh " + ;; +esac