Skip to content

Commit c96a9cb

Browse files
committed
use patched versions of kourier + cert-manager
1 parent 809e969 commit c96a9cb

File tree

2 files changed

+54
-45
lines changed

2 files changed

+54
-45
lines changed

third_party/cert-manager-latest/net-certmanager.yaml

Lines changed: 35 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ metadata:
1919
name: knative-serving-certmanager
2020
labels:
2121
app.kubernetes.io/component: net-certmanager
22-
app.kubernetes.io/version: "20231107-c09b46ca"
22+
app.kubernetes.io/version: "20231110-57baadad"
2323
app.kubernetes.io/name: knative-serving
2424
serving.knative.dev/controller: "true"
2525
networking.knative.dev/certificate-provider: cert-manager
@@ -52,7 +52,7 @@ metadata:
5252
name: config.webhook.net-certmanager.networking.internal.knative.dev
5353
labels:
5454
app.kubernetes.io/component: net-certmanager
55-
app.kubernetes.io/version: "20231107-c09b46ca"
55+
app.kubernetes.io/version: "20231110-57baadad"
5656
app.kubernetes.io/name: knative-serving
5757
networking.knative.dev/certificate-provider: cert-manager
5858
webhooks:
@@ -93,7 +93,7 @@ metadata:
9393
namespace: knative-serving
9494
labels:
9595
app.kubernetes.io/component: net-certmanager
96-
app.kubernetes.io/version: "20231107-c09b46ca"
96+
app.kubernetes.io/version: "20231110-57baadad"
9797
app.kubernetes.io/name: knative-serving
9898
networking.knative.dev/certificate-provider: cert-manager
9999

@@ -119,7 +119,7 @@ metadata:
119119
namespace: knative-serving
120120
labels:
121121
app.kubernetes.io/component: net-certmanager
122-
app.kubernetes.io/version: "20231107-c09b46ca"
122+
app.kubernetes.io/version: "20231110-57baadad"
123123
app.kubernetes.io/name: knative-serving
124124
networking.knative.dev/certificate-provider: cert-manager
125125
data:
@@ -138,23 +138,32 @@ data:
138138
# These sample configuration options may be copied out of
139139
# this block and unindented to actually change the configuration.
140140
141-
# issuerRef is a reference to the issuer for cluster external certificates used for ingress.
141+
# issuerRef is a reference to the issuer for external-domain certificates used for ingress.
142142
# IssuerRef should be either `ClusterIssuer` or `Issuer`.
143143
# Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
144144
# for more details about IssuerRef configuration.
145-
# If the issuerRef is not specified, the self-signed `knative-internal-encryption-ca` ClusterIssuer is used.
145+
# If the issuerRef is not specified, the self-signed `knative-selfsigned-issuer` ClusterIssuer is used.
146146
issuerRef: |
147147
kind: ClusterIssuer
148148
name: letsencrypt-issuer
149149
150-
# clusterInternalIssuerRef is a reference to the issuer for cluster internal certificates used for ingress.
151-
# ClusterInternalIssuerRef should be either `ClusterIssuer` or `Issuer`.
150+
# clusterLocalIssuerRef is a reference to the issuer for cluster-local-domain certificates used for ingress.
151+
# clusterLocalIssuerRef should be either `ClusterIssuer` or `Issuer`.
152152
# Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
153153
# for more details about ClusterInternalIssuerRef configuration.
154-
# If the clusterInternalIssuerRef is not specified, the self-signed `knative-internal-encryption-ca` ClusterIssuer is used.
155-
clusterInternalIssuerRef: |
154+
# If the clusterLocalIssuerRef is not specified, the self-signed `knative-selfsigned-issuer` ClusterIssuer is used.
155+
clusterLocalIssuerRef: |
156156
kind: ClusterIssuer
157-
name: knative-internal-encryption-issuer
157+
name: your-company-issuer
158+
159+
# systemInternalIssuerRef is a reference to the issuer for certificates for system-internal-tls certificates used by Knative internal components.
160+
# systemInternalIssuerRef should be either `ClusterIssuer` or `Issuer`.
161+
# Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
162+
# for more details about ClusterInternalIssuerRef configuration.
163+
# If the systemInternalIssuerRef is not specified, the self-signed `knative-selfsigned-issuer` ClusterIssuer is used.
164+
systemInternalIssuerRef: |
165+
kind: ClusterIssuer
166+
name: knative-selfsigned-issuer
158167
159168
---
160169
# Copyright 2020 The Knative Authors
@@ -178,7 +187,7 @@ metadata:
178187
namespace: knative-serving
179188
labels:
180189
app.kubernetes.io/component: net-certmanager
181-
app.kubernetes.io/version: "20231107-c09b46ca"
190+
app.kubernetes.io/version: "20231110-57baadad"
182191
app.kubernetes.io/name: knative-serving
183192
networking.knative.dev/certificate-provider: cert-manager
184193
spec:
@@ -190,15 +199,15 @@ spec:
190199
labels:
191200
app: net-certmanager-controller
192201
app.kubernetes.io/component: net-certmanager
193-
app.kubernetes.io/version: "20231107-c09b46ca"
202+
app.kubernetes.io/version: "20231110-57baadad"
194203
app.kubernetes.io/name: knative-serving
195204
spec:
196205
serviceAccountName: controller
197206
containers:
198207
- name: controller
199208
# This is the Go import path for the binary that is containerized
200209
# and substituted here.
201-
image: gcr.io/knative-nightly/knative.dev/net-certmanager/cmd/controller@sha256:b158663e24103e6b049557e3a666e6ebd8c42bf93a8224926fe21eabacb4520d
210+
image: quay.io/rlehmann/net-certmanager-controller:latest
202211
resources:
203212
requests:
204213
cpu: 30m
@@ -239,7 +248,7 @@ metadata:
239248
labels:
240249
app: net-certmanager-controller
241250
app.kubernetes.io/component: net-certmanager
242-
app.kubernetes.io/version: "20231107-c09b46ca"
251+
app.kubernetes.io/version: "20231110-57baadad"
243252
app.kubernetes.io/name: knative-serving
244253
networking.knative.dev/certificate-provider: cert-manager
245254
name: net-certmanager-controller
@@ -277,7 +286,7 @@ metadata:
277286
name: selfsigned-cluster-issuer
278287
labels:
279288
app.kubernetes.io/component: net-certmanager
280-
app.kubernetes.io/version: "20231107-c09b46ca"
289+
app.kubernetes.io/version: "20231110-57baadad"
281290
app.kubernetes.io/name: knative-serving
282291
networking.knative.dev/certificate-provider: cert-manager
283292
spec:
@@ -286,28 +295,28 @@ spec:
286295
apiVersion: cert-manager.io/v1
287296
kind: ClusterIssuer
288297
metadata:
289-
name: knative-internal-encryption-issuer
298+
name: knative-selfsigned-issuer
290299
labels:
291300
app.kubernetes.io/component: net-certmanager
292-
app.kubernetes.io/version: "20231107-c09b46ca"
301+
app.kubernetes.io/version: "20231110-57baadad"
293302
app.kubernetes.io/name: knative-serving
294303
networking.knative.dev/certificate-provider: cert-manager
295304
spec:
296305
ca:
297-
secretName: knative-internal-encryption-ca
306+
secretName: knative-selfsigned-ca
298307
---
299308
apiVersion: cert-manager.io/v1
300309
kind: Certificate
301310
metadata:
302-
name: knative-internal-encryption-ca
311+
name: knative-selfsigned-ca
303312
namespace: cert-manager # If you want to use it as a ClusterIssuer the secret must be in the cert-manager namespace.
304313
labels:
305314
app.kubernetes.io/component: net-certmanager
306-
app.kubernetes.io/version: "20231107-c09b46ca"
315+
app.kubernetes.io/version: "20231110-57baadad"
307316
app.kubernetes.io/name: knative-serving
308317
networking.knative.dev/certificate-provider: cert-manager
309318
spec:
310-
secretName: knative-internal-encryption-ca
319+
secretName: knative-selfsigned-ca
311320
commonName: knative.dev
312321
usages:
313322
- server auth
@@ -338,7 +347,7 @@ metadata:
338347
namespace: knative-serving
339348
labels:
340349
app.kubernetes.io/component: net-certmanager
341-
app.kubernetes.io/version: "20231107-c09b46ca"
350+
app.kubernetes.io/version: "20231110-57baadad"
342351
app.kubernetes.io/name: knative-serving
343352
networking.knative.dev/certificate-provider: cert-manager
344353
spec:
@@ -351,7 +360,7 @@ spec:
351360
labels:
352361
app: net-certmanager-webhook
353362
app.kubernetes.io/component: net-certmanager
354-
app.kubernetes.io/version: "20231107-c09b46ca"
363+
app.kubernetes.io/version: "20231110-57baadad"
355364
app.kubernetes.io/name: knative-serving
356365
role: net-certmanager-webhook
357366
spec:
@@ -360,7 +369,7 @@ spec:
360369
- name: webhook
361370
# This is the Go import path for the binary that is containerized
362371
# and substituted here.
363-
image: gcr.io/knative-nightly/knative.dev/net-certmanager/cmd/webhook@sha256:5d890bbbabbe36c09f1c5c026fd3f4e12e0f4a5773d816bb434dbf9a518334c4
372+
image: quay.io/rlehmann/net-certmanager-webhook:latest
364373
resources:
365374
requests:
366375
cpu: 20m
@@ -426,7 +435,7 @@ metadata:
426435
labels:
427436
role: net-certmanager-webhook
428437
app.kubernetes.io/component: net-certmanager
429-
app.kubernetes.io/version: "20231107-c09b46ca"
438+
app.kubernetes.io/version: "20231110-57baadad"
430439
app.kubernetes.io/name: knative-serving
431440
networking.knative.dev/certificate-provider: cert-manager
432441
spec:

third_party/kourier-latest/kourier.yaml

Lines changed: 19 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ metadata:
2020
networking.knative.dev/ingress-provider: kourier
2121
app.kubernetes.io/name: knative-serving
2222
app.kubernetes.io/component: net-kourier
23-
app.kubernetes.io/version: "20231102-1930e146"
23+
app.kubernetes.io/version: "20231110-1c93d51b"
2424

2525
---
2626
# Copyright 2020 The Knative Authors
@@ -45,7 +45,7 @@ metadata:
4545
labels:
4646
networking.knative.dev/ingress-provider: kourier
4747
app.kubernetes.io/component: net-kourier
48-
app.kubernetes.io/version: "20231102-1930e146"
48+
app.kubernetes.io/version: "20231110-1c93d51b"
4949
app.kubernetes.io/name: knative-serving
5050
data:
5151
envoy-bootstrap.yaml: |
@@ -55,7 +55,7 @@ data:
5555
api_type: GRPC
5656
rate_limit_settings: {}
5757
grpc_services:
58-
- envoy_grpc: {cluster_name: xds_cluster}
58+
- envoy_grpc: {cluster_name: xds_cluster}
5959
cds_config:
6060
resource_api_version: V3
6161
ads: {}
@@ -133,9 +133,9 @@ data:
133133
type: STRICT_DNS
134134
admin:
135135
access_log:
136-
- name: envoy.access_loggers.stdout
137-
typed_config:
138-
"@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
136+
- name: envoy.access_loggers.stdout
137+
typed_config:
138+
"@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
139139
address:
140140
pipe:
141141
path: /tmp/envoy.admin
@@ -168,7 +168,7 @@ metadata:
168168
labels:
169169
networking.knative.dev/ingress-provider: kourier
170170
app.kubernetes.io/component: net-kourier
171-
app.kubernetes.io/version: "20231102-1930e146"
171+
app.kubernetes.io/version: "20231110-1c93d51b"
172172
app.kubernetes.io/name: knative-serving
173173
data:
174174
_example: |
@@ -248,7 +248,7 @@ metadata:
248248
labels:
249249
networking.knative.dev/ingress-provider: kourier
250250
app.kubernetes.io/component: net-kourier
251-
app.kubernetes.io/version: "20231102-1930e146"
251+
app.kubernetes.io/version: "20231110-1c93d51b"
252252
app.kubernetes.io/name: knative-serving
253253
---
254254
apiVersion: rbac.authorization.k8s.io/v1
@@ -258,7 +258,7 @@ metadata:
258258
labels:
259259
networking.knative.dev/ingress-provider: kourier
260260
app.kubernetes.io/component: net-kourier
261-
app.kubernetes.io/version: "20231102-1930e146"
261+
app.kubernetes.io/version: "20231110-1c93d51b"
262262
app.kubernetes.io/name: knative-serving
263263
rules:
264264
- apiGroups: [""]
@@ -287,7 +287,7 @@ metadata:
287287
labels:
288288
networking.knative.dev/ingress-provider: kourier
289289
app.kubernetes.io/component: net-kourier
290-
app.kubernetes.io/version: "20231102-1930e146"
290+
app.kubernetes.io/version: "20231110-1c93d51b"
291291
app.kubernetes.io/name: knative-serving
292292
roleRef:
293293
apiGroup: rbac.authorization.k8s.io
@@ -321,7 +321,7 @@ metadata:
321321
labels:
322322
networking.knative.dev/ingress-provider: kourier
323323
app.kubernetes.io/component: net-kourier
324-
app.kubernetes.io/version: "20231102-1930e146"
324+
app.kubernetes.io/version: "20231110-1c93d51b"
325325
app.kubernetes.io/name: knative-serving
326326
spec:
327327
strategy:
@@ -343,7 +343,7 @@ spec:
343343
app: net-kourier-controller
344344
spec:
345345
containers:
346-
- image: gcr.io/knative-nightly/knative.dev/net-kourier/cmd/kourier@sha256:f79c3befc15db6e0ab1890a9488fabe6e31e1158e762922ffa56ecb72d6771fe
346+
- image: quay.io/rlehmann/kourier-controller/main.go:latest
347347
name: controller
348348
env:
349349
- name: CERTS_SECRET_NAMESPACE
@@ -395,7 +395,7 @@ spec:
395395
cpu: 200m
396396
memory: 200Mi
397397
limits:
398-
cpu: 500m
398+
cpu: "1"
399399
memory: 500Mi
400400
restartPolicy: Always
401401
serviceAccountName: net-kourier
@@ -408,7 +408,7 @@ metadata:
408408
labels:
409409
networking.knative.dev/ingress-provider: kourier
410410
app.kubernetes.io/component: net-kourier
411-
app.kubernetes.io/version: "20231102-1930e146"
411+
app.kubernetes.io/version: "20231110-1c93d51b"
412412
app.kubernetes.io/name: knative-serving
413413
spec:
414414
ports:
@@ -443,7 +443,7 @@ metadata:
443443
labels:
444444
networking.knative.dev/ingress-provider: kourier
445445
app.kubernetes.io/component: net-kourier
446-
app.kubernetes.io/version: "20231102-1930e146"
446+
app.kubernetes.io/version: "20231110-1c93d51b"
447447
app.kubernetes.io/name: knative-serving
448448
spec:
449449
strategy:
@@ -552,7 +552,7 @@ metadata:
552552
labels:
553553
networking.knative.dev/ingress-provider: kourier
554554
app.kubernetes.io/component: net-kourier
555-
app.kubernetes.io/version: "20231102-1930e146"
555+
app.kubernetes.io/version: "20231110-1c93d51b"
556556
app.kubernetes.io/name: knative-serving
557557
spec:
558558
ports:
@@ -576,7 +576,7 @@ metadata:
576576
labels:
577577
networking.knative.dev/ingress-provider: kourier
578578
app.kubernetes.io/component: net-kourier
579-
app.kubernetes.io/version: "20231102-1930e146"
579+
app.kubernetes.io/version: "20231110-1c93d51b"
580580
app.kubernetes.io/name: knative-serving
581581
spec:
582582
ports:
@@ -600,7 +600,7 @@ metadata:
600600
labels:
601601
networking.knative.dev/ingress-provider: kourier
602602
app.kubernetes.io/component: net-kourier
603-
app.kubernetes.io/version: "20231102-1930e146"
603+
app.kubernetes.io/version: "20231110-1c93d51b"
604604
app.kubernetes.io/name: knative-serving
605605
spec:
606606
minReplicas: 1
@@ -626,7 +626,7 @@ metadata:
626626
labels:
627627
networking.knative.dev/ingress-provider: kourier
628628
app.kubernetes.io/component: net-kourier
629-
app.kubernetes.io/version: "20231102-1930e146"
629+
app.kubernetes.io/version: "20231110-1c93d51b"
630630
app.kubernetes.io/name: knative-serving
631631
spec:
632632
minAvailable: 80%

0 commit comments

Comments
 (0)