Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generate Certs for Mutation/Validatiion Webhooks #214

Merged
merged 1 commit into from
May 22, 2018
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion build/Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -170,7 +170,9 @@ push-agones-sdk-image: ensure-build-image
# Generate the static install script
gen-install: ensure-build-image
docker run --rm $(common_mounts) $(DOCKER_RUN_ARGS) $(build_tag) bash -c \
'helm template --name=agones-manual $(mount_path)/install/helm/agones > $(mount_path)/install/yaml/install.yaml'
'helm template --name=agones-manual $(mount_path)/install/helm/agones \
--set agones.controller.generateTLS=false \
> $(mount_path)/install/yaml/install.yaml'

# Generate the SDK gRPC server and client code
gen-gameservers-sdk-grpc: ensure-build-image
Expand Down Expand Up @@ -271,6 +273,10 @@ gcloud-test-cluster: ensure-build-image
docker run --rm -it $(common_mounts) $(DOCKER_RUN_ARGS) $(build_tag) kubectl apply -f $(mount_path)/build/helm.yaml
docker run --rm $(common_mounts) $(DOCKER_RUN_ARGS) $(build_tag) helm init --service-account helm

clean-gcloud-test-cluster: ensure-build-image
docker run --rm -it $(common_mounts) $(DOCKER_RUN_ARGS) $(build_tag) gcloud \
deployment-manager deployments delete test-cluster

# Pulls down authentication information for kubectl against a cluster, name can be specified through CLUSTER_NAME
# (defaults to 'test-cluster')
gcloud-auth-cluster: ensure-build-image
Expand Down
1 change: 0 additions & 1 deletion cmd/controller/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,6 @@ FROM alpine:3.7
RUN apk --update add ca-certificates && \
adduser -D agones

COPY ./certs /home/agones/certs
COPY ./bin/controller /home/agones/controller

RUN chown -R agones /home/agones && \
Expand Down
4 changes: 4 additions & 0 deletions docs/installing_agones.md
Original file line number Diff line number Diff line change
Expand Up @@ -193,6 +193,10 @@ We can install Agones to the cluster using the
kubectl apply -f https://raw.githubusercontent.com/googlecloudplatform/agones/release-0.1/install.yaml
```

> Note: Installing Agones with the `intall.yaml` will setup the TLS certificates stored in this repository for securing
> kubernetes webhooks communication. If you want to generates new certificates or use your own,
> we recommend using the helm installation.

## Install using Helm

Also, we can install Agones using [Helm][helm] package manager. If you want more details and configuration
Expand Down
1 change: 1 addition & 0 deletions install/helm/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,7 @@ The following tables lists the configurable parameters of the Agones chart and t
| `agones.controller.healthCheck.failureThreshold` | Number of times before giving up (in seconds) | `3` |
| `agones.controller.healthCheck.timeoutSeconds` | Number of seconds after which the probe times out (in seconds) | `1` |
| `agones.controller.resources` | Controller resource requests/limit | `{}`
| `agones.controller.generateTLS` | Set to true to generate TLS certificates or false to provide your own certificates in `certs/*` | `true`
| `gameservers.namespaces` | a list of namespaces you are planning to use to deploy game servers | `["defaut"]` |
| `gameservers.minPort` | Minimum port to use for dynamic port allocation | `7000` |
| `gameservers.maxPort` | Maximum port to use for dynamic port allocation | `8000` |
Expand Down
File renamed without changes.
File renamed without changes.
File renamed without changes.
112 changes: 112 additions & 0 deletions install/helm/agones/templates/admissionregistration.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,112 @@
# Copyright 2018 Google Inc. All Rights Reserved.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
{{- $ca := genCA "admission-controller-ca" 3650 }}
{{- $cn := printf "agones-controller-service" }}
{{- $altName1 := printf "agones-controller-service.%s" .Values.agones.namespace }}
{{- $altName2 := printf "agones-controller-service.%s.svc" .Values.agones.namespace }}
{{- $cert := genSignedCert $cn nil (list $altName1 $altName2) 3650 $ca }}
---
apiVersion: admissionregistration.k8s.io/v1beta1
kind: ValidatingWebhookConfiguration
metadata:
name: agones-validation-webhook
namespace: {{ .Values.agones.namespace }}
webhooks:
- name: validations.stable.agones.dev
failurePolicy: Fail
clientConfig:
service:
name: agones-controller-service
namespace: {{ .Values.agones.namespace }}
path: /validate
{{- if .Values.agones.controller.generateTLS }}
caBundle: {{ b64enc $ca.Cert }}
{{- else }}
caBundle: {{ .Files.Get "certs/server.crt" | b64enc }}
{{- end }}
rules:
- apiGroups:
- stable.agones.dev
resources:
- "gameservers"
- "fleetallocations"
apiVersions:
- "v1alpha1"
operations:
- CREATE
- apiGroups:
- stable.agones.dev
resources:
- "gameserversets"
- "fleetallocations"
apiVersions:
- "v1alpha1"
operations:
- UPDATE
---
apiVersion: admissionregistration.k8s.io/v1beta1
kind: MutatingWebhookConfiguration
metadata:
name: agones-mutation-webhook
namespace: {{ .Values.agones.namespace }}
labels:
component: controller
app: {{ template "agones.name" . }}
chart: {{ template "agones.chart" . }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
webhooks:
- name: mutations.stable.agones.dev
failurePolicy: Fail
clientConfig:
service:
name: agones-controller-service
namespace: {{ .Values.agones.namespace }}
path: /mutate
{{- if .Values.agones.controller.generateTLS }}
caBundle: {{ b64enc $ca.Cert }}
{{- else }}
caBundle: {{ .Files.Get "certs/server.crt" | b64enc }}
{{- end }}
rules:
- apiGroups:
- stable.agones.dev
resources:
- "gameservers"
- "fleets"
- "fleetallocations"
apiVersions:
- "v1alpha1"
operations:
- CREATE
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "agones.fullname" . }}-cert
namespace: {{ .Values.agones.namespace }}
labels:
app: {{ template "agones.fullname" . }}
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
release: "{{ .Release.Name }}"
heritage: "{{ .Release.Service }}"
type: Opaque
data:
{{- if .Values.agones.controller.generateTLS }}
server.crt: {{ b64enc $cert.Cert }}
server.key: {{ b64enc $cert.Key }}
{{- else }}
server.crt: {{ .Files.Get "certs/server.crt" | b64enc }}
server.key: {{ .Files.Get "certs/server.key" | b64enc }}
{{- end }}
8 changes: 8 additions & 0 deletions install/helm/agones/templates/controller.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -64,3 +64,11 @@ spec:
resources:
{{ toYaml .Values.agones.controller.resources | indent 10 }}
{{- end }}
volumeMounts:
- name: certs
mountPath: /home/agones/certs
readOnly: true
volumes:
- name: certs
secret:
secretName: {{ template "agones.fullname" . }}-cert
45 changes: 0 additions & 45 deletions install/helm/agones/templates/mutatingwebhook.yaml

This file was deleted.

48 changes: 0 additions & 48 deletions install/helm/agones/templates/validatingwebhook.yaml

This file was deleted.

1 change: 1 addition & 0 deletions install/helm/agones/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ agones:
sdk: agones-sdk
controller:
resources: {}
generateTLS: true
healthCheck:
http:
port: 8080
Expand Down
Loading