Skip to content

Commit b37cadc

Browse files
authored
Merge pull request #976 from aramase/automated-cherry-pick-of-#975-upstream-release-1.2
Automated cherry pick of #975: release: update manifest and helm charts for v1.2.0
2 parents 64644f3 + f0c2228 commit b37cadc

24 files changed

+135
-179
lines changed

Makefile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ IMAGE_VERSION ?= v1.2.0
3434

3535
# Use a custom version for E2E tests if we are testing in CI
3636
ifdef CI
37-
override IMAGE_VERSION := v1.1.0-e2e-$(BUILD_COMMIT)
37+
override IMAGE_VERSION := v1.2.0-e2e-$(BUILD_COMMIT)
3838
endif
3939

4040
IMAGE_TAG=$(REGISTRY)/$(IMAGE_NAME):$(IMAGE_VERSION)

charts/secrets-store-csi-driver/Chart.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
apiVersion: v2
22
name: secrets-store-csi-driver
3-
version: 1.1.2
4-
appVersion: 1.1.2
3+
version: 1.2.0
4+
appVersion: 1.2.0
55
kubeVersion: ">=1.16.0-0"
66
description: A Helm chart to install the SecretsStore CSI Driver inside a Kubernetes cluster.
77
icon: https://github.com/kubernetes/kubernetes/blob/master/logo/logo.png

charts/secrets-store-csi-driver/README.md

Lines changed: 80 additions & 77 deletions
Large diffs are not rendered by default.

charts/secrets-store-csi-driver/crds/secrets-store.csi.x-k8s.io_secretproviderclasses.yaml

Lines changed: 1 addition & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,9 @@
1-
21
---
32
apiVersion: apiextensions.k8s.io/v1
43
kind: CustomResourceDefinition
54
metadata:
65
annotations:
7-
controller-gen.kubebuilder.io/version: v0.7.0
6+
controller-gen.kubebuilder.io/version: v0.9.0
87
creationTimestamp: null
98
name: secretproviderclasses.secrets-store.csi.x-k8s.io
109
spec:
@@ -191,9 +190,3 @@ spec:
191190
type: object
192191
served: true
193192
storage: false
194-
status:
195-
acceptedNames:
196-
kind: ""
197-
plural: ""
198-
conditions: []
199-
storedVersions: []

charts/secrets-store-csi-driver/crds/secrets-store.csi.x-k8s.io_secretproviderclasspodstatuses.yaml

Lines changed: 1 addition & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,9 @@
1-
21
---
32
apiVersion: apiextensions.k8s.io/v1
43
kind: CustomResourceDefinition
54
metadata:
65
annotations:
7-
controller-gen.kubebuilder.io/version: v0.7.0
6+
controller-gen.kubebuilder.io/version: v0.9.0
87
creationTimestamp: null
98
name: secretproviderclasspodstatuses.secrets-store.csi.x-k8s.io
109
spec:
@@ -107,9 +106,3 @@ spec:
107106
type: object
108107
served: true
109108
storage: false
110-
status:
111-
acceptedNames:
112-
kind: ""
113-
plural: ""
114-
conditions: []
115-
storedVersions: []

charts/secrets-store-csi-driver/templates/crds-upgrade-hook.yaml

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ metadata:
7878
{{ include "sscd.labels" . | indent 2 }}
7979
annotations:
8080
helm.sh/hook: pre-install,pre-upgrade
81-
helm.sh/hook-weight: "1"
81+
helm.sh/hook-weight: "10"
8282
helm.sh/hook-delete-policy: "hook-succeeded,before-hook-creation"
8383
spec:
8484
backoffLimit: 0
@@ -87,7 +87,11 @@ spec:
8787
name: {{ template "sscd.fullname" . }}-upgrade-crds
8888
{{- if .Values.linux.crds.annotations }}
8989
annotations:
90-
{{ toYaml .Values.linux.crds.annotations}}
90+
{{ toYaml .Values.linux.crds.annotations }}
91+
{{- end }}
92+
{{- if .Values.linux.crds.podLabels }}
93+
labels:
94+
{{- toYaml .Values.linux.crds.podLabels | nindent 8 }}
9195
{{- end }}
9296
spec:
9397
serviceAccountName: {{ template "sscd.fullname" . }}-upgrade-crds

charts/secrets-store-csi-driver/templates/csidriver.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,5 +10,5 @@ spec:
1010
- Ephemeral
1111
{{- if and (semverCompare ">=1.20-0" .Capabilities.KubeVersion.Version) .Values.tokenRequests }}
1212
tokenRequests:
13-
{{- toYaml .Values.tokenRequests | nindent 2}}
13+
{{- toYaml .Values.tokenRequests | nindent 2 }}
1414
{{- end }}

charts/secrets-store-csi-driver/templates/keep-crds-upgrade-hook.yaml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ metadata:
7878
{{ include "sscd.labels" . | indent 2 }}
7979
annotations:
8080
helm.sh/hook: pre-upgrade
81-
helm.sh/hook-weight: "2"
81+
helm.sh/hook-weight: "20"
8282
helm.sh/hook-delete-policy: "hook-succeeded,before-hook-creation"
8383
spec:
8484
backoffLimit: 0
@@ -89,6 +89,10 @@ spec:
8989
annotations:
9090
{{ toYaml .Values.linux.crds.annotations}}
9191
{{- end }}
92+
{{- if .Values.linux.crds.podLabels }}
93+
labels:
94+
{{- toYaml .Values.linux.crds.podLabels | nindent 8 }}
95+
{{- end }}
9296
spec:
9397
serviceAccountName: {{ template "sscd.fullname" . }}-keep-crds
9498
{{- if .Values.imagePullSecrets }}

charts/secrets-store-csi-driver/templates/role-rotation.yaml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
{{ if .Values.enableSecretRotation }}
2-
32
---
43
apiVersion: rbac.authorization.k8s.io/v1
54
kind: ClusterRole

charts/secrets-store-csi-driver/templates/role-syncsecret.yaml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
{{ if .Values.syncSecret.enabled }}
2-
32
---
43
apiVersion: rbac.authorization.k8s.io/v1
54
kind: ClusterRole

charts/secrets-store-csi-driver/templates/role-tokenrequest.yaml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
{{ if .Values.tokenRequests }}
2-
32
---
43
apiVersion: rbac.authorization.k8s.io/v1
54
kind: ClusterRole

charts/secrets-store-csi-driver/templates/role.yaml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
{{ if .Values.rbac.install }}
2-
32
---
43
apiVersion: rbac.authorization.k8s.io/v1
54
kind: ClusterRole

charts/secrets-store-csi-driver/templates/secrets-store-csi-driver-windows.yaml

Lines changed: 3 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
{{- if .Values.windows.enabled}}
1+
{{- if .Values.windows.enabled }}
22
kind: DaemonSet
33
apiVersion: apps/v1
44
metadata:
@@ -49,12 +49,6 @@ spec:
4949
- --mode=kubelet-registration-probe
5050
initialDelaySeconds: 30
5151
timeoutSeconds: 15
52-
env:
53-
- name: KUBE_NODE_NAME
54-
valueFrom:
55-
fieldRef:
56-
apiVersion: v1
57-
fieldPath: spec.nodeName
5852
imagePullPolicy: {{ .Values.windows.registrarImage.pullPolicy }}
5953
volumeMounts:
6054
- name: plugin-dir
@@ -138,7 +132,7 @@ spec:
138132
{{- end }}
139133
{{- end }}
140134
{{- if .Values.windows.volumeMounts }}
141-
{{- toYaml .Values.windows.volumeMounts | nindent 12}}
135+
{{- toYaml .Values.windows.volumeMounts | nindent 12 }}
142136
{{- end }}
143137
{{- with .Values.windows.driver.resources }}
144138
resources:
@@ -191,7 +185,7 @@ spec:
191185
{{- end }}
192186
{{- end }}
193187
{{- if .Values.windows.volumes }}
194-
{{- toYaml .Values.windows.volumes | nindent 8}}
188+
{{- toYaml .Values.windows.volumes | nindent 8 }}
195189
{{- end }}
196190
nodeSelector:
197191
kubernetes.io/os: windows

charts/secrets-store-csi-driver/templates/secrets-store-csi-driver.yaml

Lines changed: 4 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
{{- if .Values.linux.enabled}}
1+
{{- if .Values.linux.enabled }}
22
kind: DaemonSet
33
apiVersion: apps/v1
44
metadata:
@@ -49,12 +49,6 @@ spec:
4949
- --mode=kubelet-registration-probe
5050
initialDelaySeconds: 30
5151
timeoutSeconds: 15
52-
env:
53-
- name: KUBE_NODE_NAME
54-
valueFrom:
55-
fieldRef:
56-
apiVersion: v1
57-
fieldPath: spec.nodeName
5852
imagePullPolicy: {{ .Values.linux.registrarImage.pullPolicy }}
5953
volumeMounts:
6054
- name: plugin-dir
@@ -141,7 +135,7 @@ spec:
141135
{{- end }}
142136
{{- end }}
143137
{{- if .Values.linux.volumeMounts }}
144-
{{- toYaml .Values.linux.volumeMounts | nindent 12}}
138+
{{- toYaml .Values.linux.volumeMounts | nindent 12 }}
145139
{{- end }}
146140
{{- with .Values.linux.driver.resources }}
147141
resources:
@@ -191,10 +185,10 @@ spec:
191185
hostPath:
192186
path: "{{ $path }}"
193187
type: DirectoryOrCreate
194-
{{- end}}
188+
{{- end }}
195189
{{- end }}
196190
{{- if .Values.linux.volumes }}
197-
{{- toYaml .Values.linux.volumes | nindent 8}}
191+
{{- toYaml .Values.linux.volumes | nindent 8 }}
198192
{{- end }}
199193
nodeSelector:
200194
kubernetes.io/os: linux

charts/secrets-store-csi-driver/values.yaml

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,16 @@ linux:
22
enabled: true
33
image:
44
repository: k8s.gcr.io/csi-secrets-store/driver
5-
tag: v1.1.2
5+
tag: v1.2.0
66
pullPolicy: IfNotPresent
77

88
crds:
99
image:
1010
repository: k8s.gcr.io/csi-secrets-store/driver-crds
11-
tag: v1.1.2
11+
tag: v1.2.0
1212
pullPolicy: IfNotPresent
1313
annotations: {}
14+
podLabels: {}
1415

1516
## Prevent the CSI driver from being scheduled on virtual-kubelet nodes
1617
affinity:
@@ -34,7 +35,7 @@ linux:
3435

3536
registrarImage:
3637
repository: k8s.gcr.io/sig-storage/csi-node-driver-registrar
37-
tag: v2.5.0
38+
tag: v2.5.1
3839
pullPolicy: IfNotPresent
3940

4041
registrar:
@@ -49,7 +50,7 @@ linux:
4950

5051
livenessProbeImage:
5152
repository: k8s.gcr.io/sig-storage/livenessprobe
52-
tag: v2.6.0
53+
tag: v2.7.0
5354
pullPolicy: IfNotPresent
5455

5556
livenessProbe:
@@ -67,9 +68,9 @@ linux:
6768
maxUnavailable: 1
6869

6970
kubeletRootDir: /var/lib/kubelet
70-
providersDir: /etc/kubernetes/secrets-store-csi-providers
71-
additionalProvidersDirs:
72-
- /var/run/secrets-store-csi-providers
71+
providersDir: /var/run/secrets-store-csi-providers
72+
additionalProvidersDirs:
73+
- /etc/kubernetes/secrets-store-csi-providers
7374
nodeSelector: {}
7475
tolerations: []
7576
metricsAddr: ":8095"
@@ -94,7 +95,7 @@ windows:
9495
enabled: false
9596
image:
9697
repository: k8s.gcr.io/csi-secrets-store/driver
97-
tag: v1.1.2
98+
tag: v1.2.0
9899
pullPolicy: IfNotPresent
99100

100101
## Prevent the CSI driver from being scheduled on virtual-kubelet nodes
@@ -119,7 +120,7 @@ windows:
119120

120121
registrarImage:
121122
repository: k8s.gcr.io/sig-storage/csi-node-driver-registrar
122-
tag: v2.5.0
123+
tag: v2.5.1
123124
pullPolicy: IfNotPresent
124125

125126
registrar:
@@ -134,7 +135,7 @@ windows:
134135

135136
livenessProbeImage:
136137
repository: k8s.gcr.io/sig-storage/livenessprobe
137-
tag: v2.6.0
138+
tag: v2.7.0
138139
pullPolicy: IfNotPresent
139140

140141
livenessProbe:

deploy/secrets-store-csi-driver-windows.yaml

Lines changed: 3 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ spec:
1717
serviceAccountName: secrets-store-csi-driver
1818
containers:
1919
- name: node-driver-registrar
20-
image: k8s.gcr.io/sig-storage/csi-node-driver-registrar:v2.5.0
20+
image: k8s.gcr.io/sig-storage/csi-node-driver-registrar:v2.5.1
2121
args:
2222
- --v=5
2323
- "--csi-address=unix://C:\\csi\\csi.sock"
@@ -30,12 +30,6 @@ spec:
3030
- --mode=kubelet-registration-probe
3131
initialDelaySeconds: 30
3232
timeoutSeconds: 15
33-
env:
34-
- name: KUBE_NODE_NAME
35-
valueFrom:
36-
fieldRef:
37-
apiVersion: v1
38-
fieldPath: spec.nodeName
3933
imagePullPolicy: IfNotPresent
4034
volumeMounts:
4135
- name: plugin-dir
@@ -50,7 +44,7 @@ spec:
5044
cpu: 100m
5145
memory: 100Mi
5246
- name: secrets-store
53-
image: k8s.gcr.io/csi-secrets-store/driver:v1.1.2
47+
image: k8s.gcr.io/csi-secrets-store/driver:v1.2.0
5448
args:
5549
- "--endpoint=$(CSI_ENDPOINT)"
5650
- "--nodeid=$(KUBE_NODE_NAME)"
@@ -99,7 +93,7 @@ spec:
9993
- name: providers-dir
10094
mountPath: C:\k\secrets-store-csi-providers
10195
- name: liveness-probe
102-
image: k8s.gcr.io/sig-storage/livenessprobe:v2.6.0
96+
image: k8s.gcr.io/sig-storage/livenessprobe:v2.7.0
10397
imagePullPolicy: IfNotPresent
10498
args:
10599
- "--csi-address=unix://C:\\csi\\csi.sock"

deploy/secrets-store-csi-driver.yaml

Lines changed: 5 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ spec:
1717
serviceAccountName: secrets-store-csi-driver
1818
containers:
1919
- name: node-driver-registrar
20-
image: k8s.gcr.io/sig-storage/csi-node-driver-registrar:v2.5.0
20+
image: k8s.gcr.io/sig-storage/csi-node-driver-registrar:v2.5.1
2121
args:
2222
- --v=5
2323
- --csi-address=/csi/csi.sock
@@ -30,12 +30,6 @@ spec:
3030
- --mode=kubelet-registration-probe
3131
initialDelaySeconds: 30
3232
timeoutSeconds: 15
33-
env:
34-
- name: KUBE_NODE_NAME
35-
valueFrom:
36-
fieldRef:
37-
apiVersion: v1
38-
fieldPath: spec.nodeName
3933
imagePullPolicy: IfNotPresent
4034
volumeMounts:
4135
- name: plugin-dir
@@ -50,12 +44,12 @@ spec:
5044
cpu: 10m
5145
memory: 20Mi
5246
- name: secrets-store
53-
image: k8s.gcr.io/csi-secrets-store/driver:v1.1.2
47+
image: k8s.gcr.io/csi-secrets-store/driver:v1.2.0
5448
args:
5549
- "--endpoint=$(CSI_ENDPOINT)"
5650
- "--nodeid=$(KUBE_NODE_NAME)"
57-
- "--provider-volume=/etc/kubernetes/secrets-store-csi-providers"
58-
- "--additional-provider-volume-paths=/var/run/secrets-store-csi-providers"
51+
- "--provider-volume=/var/run/secrets-store-csi-providers"
52+
- "--additional-provider-volume-paths=/etc/kubernetes/secrets-store-csi-providers"
5953
- "--metrics-addr=:8095"
6054
- "--enable-secret-rotation=false"
6155
- "--rotation-poll-interval=2m"
@@ -105,7 +99,7 @@ spec:
10599
cpu: 50m
106100
memory: 100Mi
107101
- name: liveness-probe
108-
image: k8s.gcr.io/sig-storage/livenessprobe:v2.6.0
102+
image: k8s.gcr.io/sig-storage/livenessprobe:v2.7.0
109103
imagePullPolicy: IfNotPresent
110104
args:
111105
- --csi-address=/csi/csi.sock

deploy/secrets-store.csi.x-k8s.io_secretproviderclasses.yaml

Lines changed: 1 addition & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,9 @@
1-
21
---
32
apiVersion: apiextensions.k8s.io/v1
43
kind: CustomResourceDefinition
54
metadata:
65
annotations:
7-
controller-gen.kubebuilder.io/version: v0.7.0
6+
controller-gen.kubebuilder.io/version: v0.9.0
87
creationTimestamp: null
98
name: secretproviderclasses.secrets-store.csi.x-k8s.io
109
spec:
@@ -191,9 +190,3 @@ spec:
191190
type: object
192191
served: true
193192
storage: false
194-
status:
195-
acceptedNames:
196-
kind: ""
197-
plural: ""
198-
conditions: []
199-
storedVersions: []

0 commit comments

Comments
 (0)