Skip to content

Commit

Permalink
tweaking
Browse files Browse the repository at this point in the history
  • Loading branch information
garethahealy committed Dec 7, 2023
1 parent e1d53cd commit 32227f2
Show file tree
Hide file tree
Showing 4 changed files with 62 additions and 22 deletions.
3 changes: 3 additions & 0 deletions .github/workflows/gatekeeper-k8s-integrationtests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,9 @@ jobs:
echo "## namespaces:"
kubectl get namespaces
echo "## deployments:"
kubectl get deployments --all-namespaces
echo "## pods:"
kubectl get pods --all-namespaces
Expand Down
44 changes: 25 additions & 19 deletions _test/deploy-gatekeeper.sh
Original file line number Diff line number Diff line change
Expand Up @@ -44,30 +44,36 @@ deploy_gatekeeper() {
echo ""
echo "Deploying gatekeeper ${gatekeeper_version}..."
oc create --save-config -f https://raw.githubusercontent.com/open-policy-agent/gatekeeper/${gatekeeper_version}/deploy/gatekeeper.yaml
oc create -f gatekeeper/config.yml -n gatekeeper-system
oc create -f gatekeeper/gatekeeper-template-manager.yml
oc create --save-config -f gatekeeper/config.yml -n gatekeeper-system
oc create --save-config -f gatekeeper/gatekeeper-template-manager.yml

oc scale --replicas=0 deployment/gatekeeper-audit --timeout=30s -n gatekeeper-system
oc scale --replicas=0 deployment/gatekeeper-controller-manager --timeout=30s -n gatekeeper-system
if [[ $(kubectl get namespace openshift --no-headers=true | wc -l) -eq 1 ]]; then
echo ""
echo "Scaling down pods so we can patch offline..."
oc scale --replicas=0 deployment/gatekeeper-audit --timeout=30s -n gatekeeper-system
oc scale --replicas=0 deployment/gatekeeper-controller-manager --timeout=30s -n gatekeeper-system

echo ""
echo "Patching gatekeeper to remove runAsUser to work on OCP..."
oc patch deployment/gatekeeper-audit --type json -p='[{"op": "remove", "path": "/spec/template/spec/containers/0/securityContext/runAsUser"}]' -n gatekeeper-system
oc patch deployment/gatekeeper-controller-manager --type json -p='[{"op": "remove", "path": "/spec/template/spec/containers/0/securityContext/runAsUser"}]' -n gatekeeper-system
oc apply -f gatekeeper/config-ocp.yml -n gatekeeper-system

echo ""
echo "Patching gatekeeper to enable emit-admission-events..."
oc patch deployment/gatekeeper-audit --type json -p='[{"op": "add", "path": "/spec/template/spec/containers/0/args/-", "value": "--emit-admission-events=true" }]' -n gatekeeper-system
oc patch deployment/gatekeeper-controller-manager --type json -p='[{"op": "add", "path": "/spec/template/spec/containers/0/args/-", "value": "--emit-admission-events=true" }]' -n gatekeeper-system
echo ""
echo "Patching gatekeeper to remove runAsUser to work on OCP..."
oc patch deployment/gatekeeper-audit --type json -p='[{"op": "remove", "path": "/spec/template/spec/containers/0/securityContext/runAsUser"}]' -n gatekeeper-system
oc patch deployment/gatekeeper-controller-manager --type json -p='[{"op": "remove", "path": "/spec/template/spec/containers/0/securityContext/runAsUser"}]' -n gatekeeper-system

echo ""
echo "Patching gatekeeper to include core namespaces in exempt-namespace..."
oc get deployment/gatekeeper-controller-manager -n gatekeeper-system -o json | jq ".spec.template.spec.containers[0].args |= . + [${excludedNamespacesComma}]" | oc apply -f -
echo ""
echo "Patching gatekeeper to enable emit-admission-events..."
oc patch deployment/gatekeeper-audit --type json -p='[{"op": "add", "path": "/spec/template/spec/containers/0/args/-", "value": "--emit-admission-events=true" }]' -n gatekeeper-system
oc patch deployment/gatekeeper-controller-manager --type json -p='[{"op": "add", "path": "/spec/template/spec/containers/0/args/-", "value": "--emit-admission-events=true" }]' -n gatekeeper-system

echo ""
echo "Waiting for gatekeeper to be ready..."
oc scale --replicas=1 deployment/gatekeeper-audit -n gatekeeper-system
oc scale --replicas=3 deployment/gatekeeper-controller-manager -n gatekeeper-system
echo ""
echo "Patching gatekeeper to include core namespaces in exempt-namespace..."
oc get deployment/gatekeeper-controller-manager -n gatekeeper-system -o json | jq ".spec.template.spec.containers[0].args |= . + [${excludedNamespacesComma}]" | oc apply -f -

echo ""
echo "Waiting for gatekeeper to be ready..."
oc scale --replicas=1 deployment/gatekeeper-audit -n gatekeeper-system
oc scale --replicas=3 deployment/gatekeeper-controller-manager -n gatekeeper-system
fi

oc rollout status deployment/gatekeeper-audit -n gatekeeper-system --watch=true --timeout=10m
oc rollout status deployment/gatekeeper-controller-manager -n gatekeeper-system --watch=true --timeout=10m
Expand Down
34 changes: 34 additions & 0 deletions gatekeeper/config-ocp.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
---
apiVersion: config.gatekeeper.sh/v1alpha1
kind: Config
metadata:
name: config
spec:
readiness:
statsEnabled: true
sync:
syncOnly:
- version: "v1"
group: ""
kind: "Namespace"
- version: "v1"
group: ""
kind: "ServiceAccount"
- version: "v1"
group: ""
kind: "PersistentVolumeClaim"
- version: "v1"
group: "networking.k8s.io"
kind: "NetworkPolicy"
- version: "v1"
group: ""
kind: "Service"
- version: "v1"
group: "monitoring.coreos.com"
kind: "ServiceMonitor"
- version: "v1"
group: "apps"
kind: "Deployment"
- version: "v1"
group: "policy"
kind: "PodDisruptionBudget"
3 changes: 0 additions & 3 deletions gatekeeper/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,6 @@ spec:
- version: "v1"
group: ""
kind: "Service"
- version: "v1"
group: "monitoring.coreos.com"
kind: "ServiceMonitor"
- version: "v1"
group: "apps"
kind: "Deployment"
Expand Down

0 comments on commit 32227f2

Please sign in to comment.