debian-mirror-gitlab/app/models/clusters/applications/cert_manager.rb

130 lines
3.7 KiB
Ruby
Raw Normal View History

2019-02-15 15:39:39 +05:30
# frozen_string_literal: true
module Clusters
module Applications
2021-03-11 19:13:27 +05:30
# DEPRECATED for removal in %14.0
# See https://gitlab.com/groups/gitlab-org/-/epics/4280
2019-07-07 11:18:12 +05:30
class CertManager < ApplicationRecord
2020-04-08 14:13:33 +05:30
VERSION = 'v0.10.1'
CRD_VERSION = '0.10'
2019-02-15 15:39:39 +05:30
self.table_name = 'clusters_applications_cert_managers'
include ::Clusters::Concerns::ApplicationCore
include ::Clusters::Concerns::ApplicationStatus
include ::Clusters::Concerns::ApplicationVersion
include ::Clusters::Concerns::ApplicationData
2023-01-13 00:05:48 +05:30
attribute :version, default: VERSION
after_initialize :set_default_email, if: :new_record?
2019-02-15 15:39:39 +05:30
validates :email, presence: true
def chart
2019-12-04 20:38:33 +05:30
'certmanager/cert-manager'
end
def repository
'https://charts.jetstack.io'
2019-02-15 15:39:39 +05:30
end
def install_command
2021-01-29 00:20:46 +05:30
helm_command_module::InstallCommand.new(
2019-02-15 15:39:39 +05:30
name: 'certmanager',
2019-12-04 20:38:33 +05:30
repository: repository,
2019-02-15 15:39:39 +05:30
version: VERSION,
rbac: cluster.platform_kubernetes_rbac?,
chart: chart,
files: files.merge(cluster_issuer_file),
2019-12-04 20:38:33 +05:30
preinstall: pre_install_script,
2020-10-24 23:57:45 +05:30
postinstall: post_install_script
2019-02-15 15:39:39 +05:30
)
end
2019-10-12 21:52:04 +05:30
def uninstall_command
2021-01-29 00:20:46 +05:30
helm_command_module::DeleteCommand.new(
2019-10-12 21:52:04 +05:30
name: 'certmanager',
rbac: cluster.platform_kubernetes_rbac?,
files: files,
2020-10-24 23:57:45 +05:30
postdelete: post_delete_script
2019-10-12 21:52:04 +05:30
)
end
2019-02-15 15:39:39 +05:30
private
2023-01-13 00:05:48 +05:30
def set_default_email
self.email ||= self.cluster&.user&.email
end
2019-12-04 20:38:33 +05:30
def pre_install_script
[
apply_file("https://raw.githubusercontent.com/jetstack/cert-manager/release-#{CRD_VERSION}/deploy/manifests/00-crds.yaml"),
"kubectl label --overwrite namespace #{Gitlab::Kubernetes::Helm::NAMESPACE} certmanager.k8s.io/disable-validation=true"
]
end
2019-02-15 15:39:39 +05:30
def post_install_script
2019-12-04 20:38:33 +05:30
[retry_command(apply_file('/data/helm/certmanager/config/cluster_issuer.yaml'))]
end
def retry_command(command)
2021-03-08 18:12:59 +05:30
Gitlab::Kubernetes::PodCmd.retry_command(command, times: 90)
2019-10-12 21:52:04 +05:30
end
def post_delete_script
[
delete_private_key,
delete_crd('certificates.certmanager.k8s.io'),
2019-12-04 20:38:33 +05:30
delete_crd('certificaterequests.certmanager.k8s.io'),
delete_crd('challenges.certmanager.k8s.io'),
2019-10-12 21:52:04 +05:30
delete_crd('clusterissuers.certmanager.k8s.io'),
2019-12-04 20:38:33 +05:30
delete_crd('issuers.certmanager.k8s.io'),
delete_crd('orders.certmanager.k8s.io')
2019-10-12 21:52:04 +05:30
].compact
end
def private_key_name
@private_key_name ||= cluster_issuer_content.dig('spec', 'acme', 'privateKeySecretRef', 'name')
end
def delete_private_key
return unless private_key_name.present?
args = %W(secret -n #{Gitlab::Kubernetes::Helm::NAMESPACE} #{private_key_name} --ignore-not-found)
Gitlab::Kubernetes::KubectlCmd.delete(*args)
end
def delete_crd(definition)
Gitlab::Kubernetes::KubectlCmd.delete("crd", definition, "--ignore-not-found")
2019-02-15 15:39:39 +05:30
end
2019-12-04 20:38:33 +05:30
def apply_file(filename)
Gitlab::Kubernetes::KubectlCmd.apply_file(filename)
end
2019-02-15 15:39:39 +05:30
def cluster_issuer_file
{
'cluster_issuer.yaml': cluster_issuer_yaml_content
}
end
def cluster_issuer_yaml_content
YAML.dump(cluster_issuer_content.deep_merge(cluster_issue_overlay))
end
def cluster_issuer_content
YAML.safe_load(File.read(cluster_issuer_file_path))
end
def cluster_issue_overlay
{ "spec" => { "acme" => { "email" => self.email } } }
end
def cluster_issuer_file_path
Rails.root.join('vendor', 'cert_manager', 'cluster_issuer.yaml')
end
end
end
end