Skip to content

Commit

Permalink
[operator] support cutom autocert-certPeriod time by days (#1249)
Browse files Browse the repository at this point in the history
* support cutom autocert certPeriod time by years

* revert

* polish

* update

* remove some example

---------

Co-authored-by: Jacob Aronoff <jaronoff97@users.noreply.github.com>
Co-authored-by: Tyler Helmuth <12352919+TylerHelmuth@users.noreply.github.com>
  • Loading branch information
3 people committed Jul 12, 2024
1 parent 9ecddbf commit 7ff3106
Show file tree
Hide file tree
Showing 15 changed files with 34 additions and 22 deletions.
2 changes: 1 addition & 1 deletion charts/opentelemetry-operator/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
apiVersion: v2
name: opentelemetry-operator
version: 0.64.1
version: 0.64.2
description: OpenTelemetry Operator Helm chart for Kubernetes
type: application
home: https://opentelemetry.io/
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
annotations:
cert-manager.io/inject-ca-from: default/example-opentelemetry-operator-serving-cert
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down Expand Up @@ -91,7 +91,7 @@ metadata:
annotations:
cert-manager.io/inject-ca-from: default/example-opentelemetry-operator-serving-cert
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand All @@ -30,7 +30,7 @@ apiVersion: cert-manager.io/v1
kind: Issuer
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down Expand Up @@ -223,7 +223,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand All @@ -242,7 +242,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand All @@ -26,7 +26,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ apiVersion: apps/v1
kind: Deployment
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ apiVersion: v1
kind: Service
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down Expand Up @@ -32,7 +32,7 @@ apiVersion: v1
kind: Service
metadata:
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
name: opentelemetry-operator
namespace: default
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
name: "example-opentelemetry-operator-cert-manager"
namespace: default
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
name: "example-opentelemetry-operator-metrics"
namespace: default
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down Expand Up @@ -44,7 +44,7 @@ metadata:
name: "example-opentelemetry-operator-webhook"
namespace: default
labels:
helm.sh/chart: opentelemetry-operator-0.64.1
helm.sh/chart: opentelemetry-operator-0.64.2
app.kubernetes.io/name: opentelemetry-operator
app.kubernetes.io/version: "0.103.0"
app.kubernetes.io/managed-by: Helm
Expand Down
5 changes: 3 additions & 2 deletions charts/opentelemetry-operator/templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -110,8 +110,9 @@ a cert is loaded from an existing secret or is provided via `.Values`
{{- end }}
{{- else }}
{{- $altNames := list ( printf "%s-webhook.%s" (include "opentelemetry-operator.fullname" .) .Release.Namespace ) ( printf "%s-webhook.%s.svc" (include "opentelemetry-operator.fullname" .) .Release.Namespace ) -}}
{{- $ca := genCA "opentelemetry-operator-operator-ca" 365 }}
{{- $cert := genSignedCert (include "opentelemetry-operator.fullname" .) nil $altNames 365 $ca }}
{{- $tmpperioddays := int .Values.admissionWebhooks.autoGenerateCert.certPeriodDays | default 365 }}
{{- $ca := genCA "opentelemetry-operator-operator-ca" $tmpperioddays }}
{{- $cert := genSignedCert (include "opentelemetry-operator.fullname" .) nil $altNames $tmpperioddays $ca }}
{{- $certCrtEnc = b64enc $cert.Cert }}
{{- $certKeyEnc = b64enc $cert.Key }}
{{- $caCertEnc = b64enc $ca.Cert }}
Expand Down
11 changes: 10 additions & 1 deletion charts/opentelemetry-operator/values.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -1571,11 +1571,20 @@
"examples": [
true
]
},
"certPeriodDays": {
"type": "integer",
"default": 365,
"title": "Cert period time in days.",
"examples": [
365
]
}
},
"examples": [{
"enabled": true,
"recreate": true
"recreate": true,
"certPeriodDays": 365
}]
},
"certFile": {
Expand Down
2 changes: 2 additions & 0 deletions charts/opentelemetry-operator/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -260,6 +260,8 @@ admissionWebhooks:
enabled: true
# If set to true, new webhook key/certificate is generated on helm upgrade.
recreate: true
# Cert period time in days. The default is 365 days.
certPeriodDays: 365

## TLS Certificate Option 3: Use your own self-signed certificate.
## certManager and autoGenerateCert must be disabled and certFile, keyFile, and caFile must be set.
Expand Down

0 comments on commit 7ff3106

Please sign in to comment.