Skip to content

Commit 095ae30

Browse files
committed
feat(helm): add podLabels for the chart's pods
A multi-tenant telemetry collector commonly takes a pod's tenant from a pod label, the one signal a headerless OTLP export carries. The chart sets only its own `app` label on every pod and offers no way to add one. `podLabels` is added to every long-running pod template, next to `app`, which it cannot replace: `app` is the selector of every workload, so the render fails when podLabels sets it. The rustfs-bucket-init Job is left out, because a Job's pod template is immutable and a label change would fail the upgrade. The default render is unchanged, so manifests/ate-install/ stays as is. Signed-off-by: QuentinBisson <quentin@giantswarm.io>
1 parent 709c0f0 commit 095ae30

12 files changed

Lines changed: 31 additions & 0 deletions

‎charts/substrate/README.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,7 @@ See `values.yaml` for the full set; the important keys:
4949
| `atelet.gcpAuthForImagePulls` | `false` | Enable only when using GCP registry auth |
5050
| `credentialProvider.namespacePolicies` | `[]` | Default-deny atespace-to-namespace grants; the chart includes get-only Secret RBAC for the provider |
5151
| `ateApi.extraArgs` | `[]` | Additional command-line arguments appended to the ateapi defaults |
52+
| `podLabels` | `{}` | Labels added to every long-running pod, next to the chart's own `app` label |
5253
| `otel.endpoint` | `""` | Set to an OTLP endpoint to export traces, metrics, the actor lifecycle events and the router access log |
5354
| `otel.traces.enabled` | `true` | Set to `false` to export no traces from the router; the Go components do not honor this yet |
5455
| `otel.traces.endpoint` | `""` | OTLP endpoint for traces, overriding `otel.endpoint` |

‎charts/substrate/templates/_helpers.tpl‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -219,6 +219,20 @@ imagePullSecrets:
219219
{{- end -}}
220220
{{- end -}}
221221

222+
{{/*
223+
The podLabels entries for a pod template, as YAML map entries. Renders nothing
224+
when podLabels is empty. The chart's own `app` label is the selector of every
225+
workload, so a podLabels entry cannot replace it.
226+
*/}}
227+
{{- define "substrate.podLabels" -}}
228+
{{- with .Values.podLabels -}}
229+
{{- if hasKey . "app" -}}
230+
{{- fail "podLabels must not set app: it is the selector label of every workload in the chart" -}}
231+
{{- end -}}
232+
{{- toYaml . -}}
233+
{{- end -}}
234+
{{- end -}}
235+
222236
{{/*
223237
imagePullPolicy: global.imagePullPolicy when set, IfNotPresent otherwise. One
224238
definition so the fallback cannot drift between pods.

‎charts/substrate/templates/ate-api-server.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,6 +71,7 @@ spec:
7171
metadata:
7272
labels:
7373
app: ate-api-server
74+
{{- with include "substrate.podLabels" $ }}{{- . | nindent 8 }}{{- end }}
7475
annotations:
7576
prometheus.io/scrape: "true"
7677
prometheus.io/port: "9090"

‎charts/substrate/templates/ate-controller.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,7 @@ spec:
6565
metadata:
6666
labels:
6767
app: ate-controller
68+
{{- with include "substrate.podLabels" $ }}{{- . | nindent 8 }}{{- end }}
6869
spec:
6970
serviceAccountName: {{ include "substrate.fullname" (list "ate-controller" .) }}
7071
{{- with include "substrate.imagePullSecrets" . }}{{- . | nindent 6 }}{{- end }}

‎charts/substrate/templates/atelet.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,7 @@ spec:
104104
metadata:
105105
labels:
106106
app: atelet
107+
{{- with include "substrate.podLabels" $ }}{{- . | nindent 8 }}{{- end }}
107108
annotations:
108109
prometheus.io/scrape: "true"
109110
prometheus.io/port: "9090"

‎charts/substrate/templates/atenet-egress.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -127,6 +127,7 @@ spec:
127127
metadata:
128128
labels:
129129
app: atenet-egress
130+
{{- with include "substrate.podLabels" $ }}{{- . | nindent 8 }}{{- end }}
130131
spec:
131132
serviceAccountName: {{ include "substrate.fullname" (list "atenet-egress" .) }}
132133
securityContext:

‎charts/substrate/templates/atenet-router.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -207,6 +207,7 @@ spec:
207207
metadata:
208208
labels:
209209
app: atenet-router
210+
{{- with include "substrate.podLabels" $ }}{{- . | nindent 8 }}{{- end }}
210211
annotations:
211212
prometheus.io/scrape: "true"
212213
prometheus.io/port: "15020"

‎charts/substrate/templates/k8s-credential-provider.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,7 @@ spec:
6565
checksum/namespace-policy: {{ toJson .Values.credentialProvider.namespacePolicies | sha256sum }}
6666
labels:
6767
app: {{ include "substrate.fullname" (list "k8s-credential-provider" .) }}
68+
{{- with include "substrate.podLabels" $ }}{{- . | nindent 8 }}{{- end }}
6869
spec:
6970
serviceAccountName: {{ include "substrate.fullname" (list "k8s-credential-provider" .) }}
7071
{{- with include "substrate.imagePullSecrets" . }}{{- . | nindent 6 }}{{- end }}

‎charts/substrate/templates/pod-certificate-controller.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -138,6 +138,7 @@ spec:
138138
metadata:
139139
labels:
140140
app: podcertificate-controller
141+
{{- with include "substrate.podLabels" $ }}{{- . | nindent 8 }}{{- end }}
141142
spec:
142143
{{- with include "substrate.imagePullSecrets" . }}{{- . | nindent 6 }}{{- end }}
143144
containers:

‎charts/substrate/templates/postgres.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,7 @@ spec:
104104
metadata:
105105
labels:
106106
app: {{ $name }}
107+
{{- with include "substrate.podLabels" $ }}{{- . | nindent 8 }}{{- end }}
107108
spec:
108109
securityContext:
109110
# Group ownership of the projected certificate below, and of the data

0 commit comments

Comments
 (0)