mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-05 22:12:04 +02:00
helm: document what turning the network policies on costs
Three things the values did not say: a Prometheus outside the release stops scraping and nothing reports it, the resize hook's policy is a hook resource that uninstall leaves behind, and the DNS selectors are wrong on OpenShift.
This commit is contained in:
1 parent
f43e8eda1d
commit
1a4554bda6
2 files changed
+26
-1
No files matched your search
@@ -395,8 +395,17 @@ networkPolicy:
|
||||
port: 5432
|
||||
```
|
||||
|
||||
`kubeApiServer.cidrs` is only demanded when something in the release actually needs the API server, which is the COSI sidecar and, on an upgrade that grows a volume PVC, the resize hook. No seaweedfs component itself speaks to it.
|
||||
|
||||
Anything reaching the release from outside - an ingress controller, a Prometheus in another namespace - goes into `networkPolicy.extraIngress`, or into `networkPolicy.components.<component>.extraIngress` for a single component. See the `networkPolicy` block in `values.yaml` for the full set.
|
||||
|
||||
Two things worth knowing before you turn this on:
|
||||
|
||||
- **Monitoring stops.** The metrics ports are admitted from release pods like every other port, so with `global.seaweedfs.monitoring.enabled` the ServiceMonitors keep scraping targets a Prometheus in another namespace can no longer reach. Nothing reports it; add the scraper's namespace to `extraIngress`.
|
||||
- **The resize hook's policy is a Helm hook.** Its Job runs before the release manifest is applied, so the policy has to be a `pre-install` hook too. Helm does not garbage-collect hook resources, so on an upgrade that grows a volume PVC the policy is created and then left behind on uninstall - delete `<release>-seaweedfs-volume-resize-hook` by hand if it bothers you.
|
||||
|
||||
The DNS selectors default to CoreDNS as kubeadm, kind, EKS, GKE and AKS install it. On OpenShift, override `egress.dnsNamespaceSelector` and `egress.dnsPodSelector` to match `openshift-dns`; see the comment in `values.yaml`.
|
||||
|
||||
## OpenShift Support
|
||||
|
||||
SeaweedFS can be deployed on OpenShift or any cluster enforcing the Kubernetes "restricted" Pod Security Standard. By default, OpenShift blocks containers that run as root or use `hostPath` volumes.
|
||||
|
||||
@@ -1830,7 +1830,12 @@ networkPolicy:
|
||||
# does not leave the policy behind. Everything else is denied.
|
||||
#
|
||||
# Traffic from outside the release has to be added here. Rules are plain
|
||||
# NetworkPolicyIngressRule entries, appended to every component's policy:
|
||||
# NetworkPolicyIngressRule entries, appended to every component's policy.
|
||||
#
|
||||
# The metrics ports are covered by the same rule as everything else, so with
|
||||
# global.seaweedfs.monitoring.enabled the ServiceMonitors keep pointing at
|
||||
# ports a Prometheus outside the release can no longer reach. Nothing reports
|
||||
# that - the targets just go down - so add the scraper here:
|
||||
#
|
||||
# extraIngress:
|
||||
# # an ingress controller reaching filer/s3/admin
|
||||
@@ -1875,6 +1880,17 @@ networkPolicy:
|
||||
|
||||
# Every component resolves its peers by DNS name, so this is required
|
||||
# for the release to function at all.
|
||||
#
|
||||
# The defaults below are CoreDNS as kubeadm, kind, EKS, GKE and AKS install
|
||||
# it. OpenShift runs its resolver elsewhere and needs both overridden:
|
||||
# dnsNamespaceSelector:
|
||||
# matchLabels:
|
||||
# kubernetes.io/metadata.name: openshift-dns
|
||||
# dnsPodSelector:
|
||||
# matchLabels:
|
||||
# dns.operator.openshift.io/daemonset-dns: default
|
||||
# A node-local DNS cache is not a pod peer at all - the resolver address is
|
||||
# a link-local IP - so name it with an ipBlock in extraEgress instead.
|
||||
allowDNS: true
|
||||
dnsNamespaceSelector:
|
||||
matchLabels:
|
||||
|
||||
Reference in new issue
Block a user