Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion features/khost

This file was deleted.

19 changes: 19 additions & 0 deletions features/khost/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
## Feature: khost
### Description
<website-feature>
The khost feature adjusts Garden Linux to support running Kubernetes (vanilla) workloads.
</website-feature>

### Features
The `khost` feature adjusts Garden Linux to support running Kubernetes (vanilla) workloads and installs and configures all related packages (regarding the used hardware architecture) and tools. It adjusts the `kublets`, `sysctl` and removes any swap partition.

### Unit testing
Unit tests will ensure that the needed packages are present as well as the `kublet` is enabled within `systemd`.

### Meta
|||
|---|---|
|type|element|
|artifact|None|
|included_features|`chost`|
|excluded_features|None|
11 changes: 11 additions & 0 deletions features/khost/exec.late
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
#!/usr/bin/env bash
set -Eeuo pipefail

K8S_VERSION=v1.34.3
K8S_VERSION_REPO="${K8S_VERSION%.*}"

gpg --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg < /builder/features/khost/release.key
echo "deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/${K8S_VERSION_REPO}/deb/ /" | tee /etc/apt/sources.list.d/kubernetes.list
apt update -y
apt install -y --no-install-recommends "kubelet=${K8S_VERSION#v}*" "kubectl=${K8S_VERSION#v}*" "kubeadm=${K8S_VERSION#v}*" "cri-tools=${K8S_VERSION_REPO#v}*"

1 change: 1 addition & 0 deletions features/khost/file.exclude
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
/etc/init.d/apparmor
1 change: 1 addition & 0 deletions features/khost/file.include/etc/modules-load.d/br-nf.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
br_netfilter
2 changes: 2 additions & 0 deletions features/khost/file.include/etc/sysctl.d/20-br-nf.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
net.bridge.bridge-nf-call-iptables=1
net.bridge.bridge-nf-call-ip6tables=1
2 changes: 2 additions & 0 deletions features/khost/file.include/etc/sysctl.d/20-inotify.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
fs.inotify.max_user_instances = 8192
fs.inotify.max_user_watches = 65536
3 changes: 3 additions & 0 deletions features/khost/file.include/etc/sysctl.d/20-ip-forward.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
net.ipv4.ip_forward=1
net.ipv6.conf.all.forwarding=1

6 changes: 6 additions & 0 deletions features/khost/fstab.mod
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
#!/usr/bin/env bash
set -Eeuo pipefail

# remove any swap partition
sed '/^[^[:space:]]\+[[:space:]]\+[^[:space:]]\+[[:space:]]\+swap[[:space:]]\+/d'

5 changes: 5 additions & 0 deletions features/khost/info.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
description: 'host for kubernetes workloads (vanilla)'
type: element
features:
include:
- chost
6 changes: 6 additions & 0 deletions features/khost/pkg.include
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
apparmor
conntrack
ethtool
ipvsadm
socat
gnupg
30 changes: 30 additions & 0 deletions features/khost/release.key
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.5 (GNU/Linux)

mQENBGMHoXcBCADukGOEQyleViOgtkMVa7hKifP6POCTh+98xNW4TfHK/nBJN2sm
u4XaiUmtB9UuGt9jl8VxQg4hOMRf40coIwHsNwtSrc2R9v5Kgpvcv537QVIigVHH
WMNvXeoZkkoDIUljvbCEDWaEhS9R5OMYKd4AaJ+f1c8OELhEcV2dAQLLyjtnEaF/
qmREN+3Y9+5VcRZvQHeyBxCG+hdUGE740ixgnY2gSqZ/J4YeQntQ6pMUEhT6pbaE
10q2HUierj/im0V+ZUdCh46Lk/Rdfa5ZKlqYOiA2iN1coDPIdyqKavcdfPqSraKF
Lan2KLcZcgTxP+0+HfzKefvGEnZa11civbe9ABEBAAG0PmlzdjprdWJlcm5ldGVz
IE9CUyBQcm9qZWN0IDxpc3Y6a3ViZXJuZXRlc0BidWlsZC5vcGVuc3VzZS5vcmc+
iQE+BBMBCAAoBQJnFF34AhsDBQkIK2yBBgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIX
gAAKCRAjRlTamilkNtOACACDK9dQ8CH2Ji9C3Q926nVMUiXdyJK1onCBrQSEBqdR
LJaT6hGx5pzxkQGgUDpS9p7LA0u920HKLwGb7yIAWtyE5TAj2CYprGgpq98sfsGC
+U5T9IrAdya/BaTAkkP6gNhfMjNaK3bOWsvuLRlluKMNch4ify+IwLqc1JLG40bj
2HnKBGYkC3m0VtQfUuPQMImSLta/NwRHJMPo8jfGyManqMMxp35/ecP2rXMfb/l1
WjFDY7h+6nqXay20ljMXkN23W8wFTdvC6lq45wwM5IBnKNR/TjNNYAIizZoHFWz1
c/ecMWWWCB2S7WbY4xI3JSCOD4XIff3ie7pc68/kgPytiQIcBBMBAgAGBQJjB6F3
AAoJEM8Lkoze1k873TQP/0t2F/jltLRQMG7VCLw7+ps5JCW5FIqu/S2i9gSdNA0E
42u+LyxjG3YxmVoVRMsxeu4kErxr8bLcA4p71W/nKeqwF9VLuXKirsBC7z2syFiL
Ndl0ARnC3ENwuMVlSCwJO0MM5NiJuLOqOGYyD1XzSfnCzkXN0JGA/bfPRS5mPfoW
0OHIRZFhqE7ED6wyWpHIKT8rXkESFwszUwW/D7o1HagX7+duLt8WkrohGbxTJ215
YanOKSqyKd+6YGzDNUoGuMNPZJ5wTrThOkTzEFZ4HjmQ16w5xmcUISnCZd4nhsbS
qN/UyV9Vu3lnkautS15E4CcjP1RRzSkT0jka62vPtAzw+PiGryM1F7svuRaEnJD5
GXzj9RCUaR6vtFVvqqo4fvbA99k4XXj+dFAXW0TRZ/g2QMePW9cdWielcr+vHF4Z
2EnsAmdvF7r5e2JCOU3N8OUodebU6ws4VgRVG9gptQgfMR0vciBbNDG2Xuk1WDk1
qtscbfm5FVL36o7dkjA0x+TYCtqZIr4x3mmfAYFUqzxpfyXbSHqUJR2CoWxlyz72
XnJ7UEo/0UbgzGzscxLPDyJHMM5Dn/Ni9FVTVKlALHnFOYYSTluoYACF1DMt7NJ3
oyA0MELL0JQzEinixqxpZ1taOmVR/8pQVrqstqwqsp3RABaeZ80JbigUC29zJUVf
=Eplj
-----END PGP PUBLIC KEY BLOCK-----
1 change: 1 addition & 0 deletions features/khost/test/test_packages_musthave.py
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
from helper.tests.packages_musthave import packages_musthave as test_packages_musthave
16 changes: 16 additions & 0 deletions features/khost/test/test_systemd_unit.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
import pytest
from helper.utils import execute_remote_command
from helper.utils import validate_systemd_unit


@pytest.mark.parametrize(
"systemd_unit",
[
"kubelet"
]
)


def test_systemd_unit(client, systemd_unit, non_provisioner_chroot):
execute_remote_command(client, f"systemctl start {systemd_unit}")
validate_systemd_unit(client, f"{systemd_unit}")
Loading