Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0e3564bf72
|
||
|
|
c6ec310b0b | ||
|
|
3b77af8da1
|
@@ -50,6 +50,7 @@ sudo k3s kubectl -n flux-system get gitrepositories,kustomizations
|
||||
- VictoriaMetrics Operator 已固定现有 chart `0.66.2` 并完成分阶段 Flux HelmRelease
|
||||
接管;Metrics、Logs、Traces 与 Grafana 也已统一完成 Flux 接管;
|
||||
- External Secrets Operator 已固定 chart `2.8.0` 并完成分阶段接管;
|
||||
- SPIRE 已按官方 hardened chart `0.30.2`(SPIRE `1.15.3`)声明,使用共享
|
||||
- SPIRE 已按 hardened chart 内部 fork `0.30.2-ddupan.1`(基于上游 `0.30.2`,SPIRE
|
||||
`1.15.3`)声明,使用共享
|
||||
PostgreSQL 与独立 signing-key PVC;首次上线和 OpenBao JWT-SVID PoC 尚待合并后验证;
|
||||
- root Kustomization 与所有 brownfield 子 Kustomization 继续保持 `prune: false`。
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
---
|
||||
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
||||
kind: Kustomization
|
||||
metadata:
|
||||
name: opensandbox-pools
|
||||
namespace: flux-system
|
||||
spec:
|
||||
dependsOn:
|
||||
- name: opensandbox
|
||||
interval: 10m
|
||||
path: ./platform/sandbox-opensandbox-pools
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
timeout: 20m
|
||||
wait: true
|
||||
@@ -0,0 +1,18 @@
|
||||
---
|
||||
apiVersion: kustomize.toolkit.fluxcd.io/v1
|
||||
kind: Kustomization
|
||||
metadata:
|
||||
name: opensandbox
|
||||
namespace: flux-system
|
||||
spec:
|
||||
dependsOn:
|
||||
- name: kata
|
||||
- name: spire-agents
|
||||
interval: 10m
|
||||
path: ./platform/sandbox-opensandbox
|
||||
prune: true
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: flux-system
|
||||
timeout: 20m
|
||||
wait: true
|
||||
@@ -7,3 +7,5 @@ resources:
|
||||
- apps/spire-bootstrap.yaml
|
||||
- apps/spire-agents.yaml
|
||||
- apps/kata.yaml
|
||||
- apps/opensandbox.yaml
|
||||
- apps/opensandbox-pools.yaml
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- pools.yaml
|
||||
@@ -0,0 +1,123 @@
|
||||
---
|
||||
apiVersion: sandbox.opensandbox.io/v1alpha1
|
||||
kind: Pool
|
||||
metadata:
|
||||
name: ci-pod
|
||||
namespace: opensandbox
|
||||
spec:
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
ci.ddupan.top/backend: pod
|
||||
spec:
|
||||
containers:
|
||||
- name: sandbox
|
||||
image: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/code-interpreter:v1.1.0
|
||||
command: [/opt/opensandbox/task-executor]
|
||||
args: [-listen-addr=0.0.0.0:5758, -log-dir=/tmp]
|
||||
env:
|
||||
- name: SANDBOX_MAIN_CONTAINER
|
||||
value: sandbox
|
||||
- name: EXECD_ENVS
|
||||
value: /opt/opensandbox/.env
|
||||
- name: EXECD
|
||||
value: /opt/opensandbox/execd
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 256Mi
|
||||
limits:
|
||||
cpu: "2"
|
||||
memory: 4Gi
|
||||
volumeMounts:
|
||||
- name: opensandbox-bin
|
||||
mountPath: /opt/opensandbox
|
||||
- name: sandbox-storage
|
||||
mountPath: /var/lib/sandbox
|
||||
initContainers:
|
||||
- name: task-executor-installer
|
||||
image: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/task-executor:v0.1.0
|
||||
command: [/bin/sh, -c]
|
||||
args: [cp /workspace/server /opt/opensandbox/task-executor && chmod 0755 /opt/opensandbox/task-executor]
|
||||
volumeMounts:
|
||||
- name: opensandbox-bin
|
||||
mountPath: /opt/opensandbox
|
||||
- name: execd-installer
|
||||
image: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/execd:v1.0.22
|
||||
command: [/bin/sh, -c]
|
||||
args: [cp ./execd /opt/opensandbox/execd && cp ./bootstrap.sh /opt/opensandbox/bootstrap.sh && chmod 0755 /opt/opensandbox/execd /opt/opensandbox/bootstrap.sh]
|
||||
volumeMounts:
|
||||
- name: opensandbox-bin
|
||||
mountPath: /opt/opensandbox
|
||||
volumes:
|
||||
- name: opensandbox-bin
|
||||
emptyDir: {}
|
||||
- name: sandbox-storage
|
||||
emptyDir: {}
|
||||
capacitySpec:
|
||||
bufferMax: 1
|
||||
bufferMin: 0
|
||||
poolMax: 4
|
||||
poolMin: 0
|
||||
---
|
||||
apiVersion: sandbox.opensandbox.io/v1alpha1
|
||||
kind: Pool
|
||||
metadata:
|
||||
name: ci-vm
|
||||
namespace: opensandbox
|
||||
spec:
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
ci.ddupan.top/backend: vm
|
||||
spec:
|
||||
runtimeClassName: kata-clh-runtime-rs
|
||||
containers:
|
||||
- name: sandbox
|
||||
image: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/code-interpreter:v1.1.0
|
||||
command: [/opt/opensandbox/task-executor]
|
||||
args: [-listen-addr=0.0.0.0:5758, -log-dir=/tmp]
|
||||
env:
|
||||
- name: SANDBOX_MAIN_CONTAINER
|
||||
value: sandbox
|
||||
- name: EXECD_ENVS
|
||||
value: /opt/opensandbox/.env
|
||||
- name: EXECD
|
||||
value: /opt/opensandbox/execd
|
||||
resources:
|
||||
requests:
|
||||
cpu: 250m
|
||||
memory: 512Mi
|
||||
limits:
|
||||
cpu: "4"
|
||||
memory: 8Gi
|
||||
volumeMounts:
|
||||
- name: opensandbox-bin
|
||||
mountPath: /opt/opensandbox
|
||||
- name: sandbox-storage
|
||||
mountPath: /var/lib/sandbox
|
||||
initContainers:
|
||||
- name: task-executor-installer
|
||||
image: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/task-executor:v0.1.0
|
||||
command: [/bin/sh, -c]
|
||||
args: [cp /workspace/server /opt/opensandbox/task-executor && chmod 0755 /opt/opensandbox/task-executor]
|
||||
volumeMounts:
|
||||
- name: opensandbox-bin
|
||||
mountPath: /opt/opensandbox
|
||||
- name: execd-installer
|
||||
image: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/execd:v1.0.22
|
||||
command: [/bin/sh, -c]
|
||||
args: [cp ./execd /opt/opensandbox/execd && cp ./bootstrap.sh /opt/opensandbox/bootstrap.sh && chmod 0755 /opt/opensandbox/execd /opt/opensandbox/bootstrap.sh]
|
||||
volumeMounts:
|
||||
- name: opensandbox-bin
|
||||
mountPath: /opt/opensandbox
|
||||
volumes:
|
||||
- name: opensandbox-bin
|
||||
emptyDir: {}
|
||||
- name: sandbox-storage
|
||||
emptyDir: {}
|
||||
capacitySpec:
|
||||
bufferMax: 1
|
||||
bufferMin: 0
|
||||
poolMax: 2
|
||||
poolMin: 0
|
||||
@@ -0,0 +1,19 @@
|
||||
# OpenSandbox
|
||||
|
||||
Flux installs the upstream all-in-one OpenSandbox chart pinned to
|
||||
`helm/opensandbox/0.2.2` (`8f01e935`). The API is cluster-internal and intentionally runs a
|
||||
single replica until shared server state and HA behaviour have been validated.
|
||||
|
||||
`ci-pod` uses `runc`; `ci-vm` uses the separately managed
|
||||
`kata-clh-runtime-rs` RuntimeClass. Both Pools start at zero and create capacity
|
||||
on demand. They currently use the upstream interpreter image to validate the
|
||||
Lifecycle API and Pool allocation independently of the CI scheduler cutover.
|
||||
|
||||
The dynamic runner worker, runner image, guest-local SPIRE Agent and Docker
|
||||
sidecar are introduced only after this layer is Ready. In particular, do not
|
||||
mount the host SPIFFE CSI socket into `ci-vm`: Unix sockets do not cross the
|
||||
Kata VM boundary.
|
||||
|
||||
Smoke test both backends through the same API by creating sandboxes with
|
||||
`extensions.poolRef` set to `ci-pod` and `ci-vm`, then confirm their
|
||||
BatchSandboxes, Pods and VMMs disappear after deletion.
|
||||
@@ -0,0 +1,31 @@
|
||||
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||
kind: HelmRelease
|
||||
metadata:
|
||||
name: opensandbox
|
||||
namespace: opensandbox-system
|
||||
spec:
|
||||
chart:
|
||||
spec:
|
||||
chart: ./kubernetes/charts/opensandbox
|
||||
interval: 1h
|
||||
reconcileStrategy: Revision
|
||||
sourceRef:
|
||||
kind: GitRepository
|
||||
name: opensandbox
|
||||
driftDetection:
|
||||
mode: enabled
|
||||
install:
|
||||
strategy:
|
||||
name: RetryOnFailure
|
||||
retryInterval: 5m
|
||||
interval: 30m
|
||||
releaseName: opensandbox
|
||||
targetNamespace: opensandbox-system
|
||||
timeout: 15m
|
||||
upgrade:
|
||||
strategy:
|
||||
name: RetryOnFailure
|
||||
retryInterval: 5m
|
||||
valuesFrom:
|
||||
- kind: ConfigMap
|
||||
name: opensandbox-values
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
resources:
|
||||
- namespaces.yaml
|
||||
- repository.yaml
|
||||
- values.yaml
|
||||
- helmrelease.yaml
|
||||
@@ -0,0 +1,10 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: opensandbox-system
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: opensandbox
|
||||
@@ -0,0 +1,11 @@
|
||||
apiVersion: source.toolkit.fluxcd.io/v1
|
||||
kind: GitRepository
|
||||
metadata:
|
||||
name: opensandbox
|
||||
namespace: opensandbox-system
|
||||
spec:
|
||||
interval: 1h
|
||||
ref:
|
||||
tag: helm/opensandbox/0.2.2
|
||||
timeout: 60s
|
||||
url: https://github.com/alibaba/OpenSandbox.git
|
||||
@@ -0,0 +1,62 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: opensandbox-values
|
||||
namespace: opensandbox-system
|
||||
data:
|
||||
values.yaml: |
|
||||
opensandbox-controller:
|
||||
controller:
|
||||
logLevel: info
|
||||
replicaCount: 1
|
||||
metrics:
|
||||
enabled: true
|
||||
secure: false
|
||||
port: 8080
|
||||
resources:
|
||||
requests:
|
||||
cpu: 25m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 256Mi
|
||||
|
||||
opensandbox-server:
|
||||
server:
|
||||
replicaCount: 1
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 256Mi
|
||||
limits:
|
||||
cpu: "1"
|
||||
memory: 1Gi
|
||||
configToml: |
|
||||
[server]
|
||||
host = "0.0.0.0"
|
||||
port = 80
|
||||
api_key = ""
|
||||
|
||||
[log]
|
||||
level = "INFO"
|
||||
|
||||
[runtime]
|
||||
type = "kubernetes"
|
||||
execd_image = "sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/execd:v1.0.22"
|
||||
|
||||
[kubernetes]
|
||||
kubeconfig_path = ""
|
||||
namespace = "opensandbox"
|
||||
informer_enabled = true
|
||||
informer_resync_seconds = 300
|
||||
informer_watch_timeout_seconds = 60
|
||||
snapshot_create_timeout_seconds = 900
|
||||
workload_provider = "batchsandbox"
|
||||
batchsandbox_template_file = "/etc/opensandbox/example.batchsandbox-template.yaml"
|
||||
|
||||
[egress]
|
||||
image = "sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/egress:v1.1.6"
|
||||
mode = "dns+nft"
|
||||
|
||||
opensandbox-node-agent:
|
||||
enabled: false
|
||||
@@ -11,7 +11,8 @@ Authelia 提供;SPIRE 不替代人类 OIDC,也不承担目标服务的资源
|
||||
Flux 安装 SPIFFE hardened charts:
|
||||
|
||||
- `spire-crds` `0.6.1`;
|
||||
- `spire` `0.30.2`(SPIRE `1.15.3`);
|
||||
- 内部 fork 的 `spire` `0.30.2-ddupan.1`(SPIRE `1.15.3`),固定 Git tag
|
||||
`spire-0.30.2-ddupan.1`;
|
||||
- SPIRE Server、Agent、Controller Manager、SPIFFE CSI Driver;
|
||||
- OIDC Discovery Provider。
|
||||
|
||||
@@ -24,6 +25,12 @@ API 或 Broker API。Trust domain 是 `ddupan.top`,Kubernetes cluster name 是
|
||||
controller-manager 与 bundle publisher 使用由 sandbox Ansible bootstrap 的独立、受限
|
||||
kubeconfig。Sandbox 不运行第二套 Server 或 OIDC Provider。
|
||||
|
||||
内部 fork 仅在上游 `spire-0.30.2` 基础上暴露
|
||||
`use_pod_uid_for_agent_id`。现有 `sandbox` profile 保持 node UID 模式,供 DaemonSet
|
||||
Agent 使用;独立的 `sandbox-kata` profile 复用同一 kubeconfig,但启用 Pod UID 模式,
|
||||
供每个 Kata guest 内的临时 Agent 使用。不得把现有 `sandbox` profile 切换为 Pod UID,
|
||||
否则会改变常驻 Agent 的 parent ID。
|
||||
|
||||
## PostgreSQL bootstrap
|
||||
|
||||
SPIRE registration datastore 使用共享 CloudNativePG:
|
||||
|
||||
@@ -41,7 +41,7 @@ SPIRE Server(trust domain: ddupan.top)
|
||||
|
||||
| 项目 | 当前值 |
|
||||
|---|---|
|
||||
| SPIRE chart | `0.30.2` |
|
||||
| SPIRE chart | `0.30.2-ddupan.1`(内部 fork,基于 `0.30.2`) |
|
||||
| SPIRE | `1.15.3` |
|
||||
| SPIRE CRDs chart | `0.6.1` |
|
||||
| trust domain | `ddupan.top` |
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
apiVersion: source.toolkit.fluxcd.io/v1
|
||||
kind: GitRepository
|
||||
metadata:
|
||||
name: spiffe-hardened-fork
|
||||
namespace: spire-mgmt
|
||||
spec:
|
||||
interval: 1h
|
||||
ref:
|
||||
tag: spire-0.30.2-ddupan.1
|
||||
timeout: 60s
|
||||
url: http://gitea-http.gitea.svc.cluster.local:3000/panxiao81/helm-charts-hardened.git
|
||||
@@ -6,12 +6,12 @@ metadata:
|
||||
spec:
|
||||
chart:
|
||||
spec:
|
||||
chart: spire
|
||||
chart: ./charts/spire
|
||||
interval: 1h
|
||||
reconcileStrategy: Revision
|
||||
sourceRef:
|
||||
kind: HelmRepository
|
||||
name: spiffe-hardened
|
||||
version: 0.30.2
|
||||
kind: GitRepository
|
||||
name: spiffe-hardened-fork
|
||||
dependsOn:
|
||||
- name: spire-crds
|
||||
namespace: spire-mgmt
|
||||
|
||||
@@ -12,6 +12,7 @@ configMapGenerator:
|
||||
resources:
|
||||
- namespaces.yaml
|
||||
- helmrepository.yaml
|
||||
- gitrepository-fork.yaml
|
||||
- helmrelease-crds.yaml
|
||||
- helmrelease.yaml
|
||||
- httproute.yaml
|
||||
|
||||
@@ -51,6 +51,11 @@ spire-server:
|
||||
kubeConfigName: sandbox
|
||||
serviceAccountAllowList:
|
||||
- spire-system:spire-agent
|
||||
sandbox-kata:
|
||||
kubeConfigName: sandbox
|
||||
serviceAccountAllowList:
|
||||
- spire-smoke:spire-smoke
|
||||
usePodUIDForAgentID: true
|
||||
externalControllerManagers:
|
||||
enabled: true
|
||||
clusters:
|
||||
|
||||
Reference in New Issue
Block a user