From 583e62a44a0946ec3edbaa8bc27918982e5b1e2f Mon Sep 17 00:00:00 2001 From: Stavros Kois <47820033+stavros-k@users.noreply.github.com> Date: Fri, 29 Dec 2023 14:30:59 +0200 Subject: [PATCH] Pgadmin - migrate storage section (adds acl) (#1966) * update values * add migration * update templates * bump version * update ui * fix migration * reduce diff * ci migration * remove redundant code --- library/ix-dev/community/pgadmin/Chart.yaml | 2 +- .../community/pgadmin/ci/basic-values.yaml | 3 +- .../community/pgadmin/ci/extra-values.yaml | 9 +- .../community/pgadmin/ci/hostnet-values.yaml | 3 +- .../community/pgadmin/ci/https-values.yaml | 3 +- .../community/pgadmin/migrations/migrate | 73 ++++++ .../ix-dev/community/pgadmin/questions.yaml | 216 ++++++++++++------ .../pgadmin/templates/_persistence.tpl | 39 ++-- .../community/pgadmin/templates/_pgadmin.tpl | 2 +- library/ix-dev/community/pgadmin/values.yaml | 3 +- 10 files changed, 253 insertions(+), 100 deletions(-) create mode 100755 library/ix-dev/community/pgadmin/migrations/migrate diff --git a/library/ix-dev/community/pgadmin/Chart.yaml b/library/ix-dev/community/pgadmin/Chart.yaml index 2cedf4f38c..fe88e7cba7 100644 --- a/library/ix-dev/community/pgadmin/Chart.yaml +++ b/library/ix-dev/community/pgadmin/Chart.yaml @@ -3,7 +3,7 @@ description: pgAdmin is the most popular and feature rich Open Source administra annotations: title: pgAdmin type: application -version: 1.1.8 +version: 1.2.0 apiVersion: v2 appVersion: '8.1' kubeVersion: '>=1.16.0-0' diff --git a/library/ix-dev/community/pgadmin/ci/basic-values.yaml b/library/ix-dev/community/pgadmin/ci/basic-values.yaml index 63e5e0a201..70c6574f2f 100644 --- a/library/ix-dev/community/pgadmin/ci/basic-values.yaml +++ b/library/ix-dev/community/pgadmin/ci/basic-values.yaml @@ -7,5 +7,4 @@ pgadminConfig: pgadminStorage: config: - type: hostPath - hostPath: /mnt/{{ .Release.Namespace }}/config + type: pvc diff --git a/library/ix-dev/community/pgadmin/ci/extra-values.yaml b/library/ix-dev/community/pgadmin/ci/extra-values.yaml index d658cfd19e..ae3f21bd47 100644 --- a/library/ix-dev/community/pgadmin/ci/extra-values.yaml +++ b/library/ix-dev/community/pgadmin/ci/extra-values.yaml @@ -7,12 +7,9 @@ pgadminNetwork: pgadminStorage: config: - type: hostPath - hostPath: /mnt/{{ .Release.Namespace }}/config + type: pvc additionalStorages: - - type: hostPath - hostPath: /mnt/{{ .Release.Namespace }}/db1 + - type: pvc mountPath: /db1 - - type: hostPath - hostPath: /mnt/{{ .Release.Namespace }}/db2 + - type: pvc mountPath: /db2 diff --git a/library/ix-dev/community/pgadmin/ci/hostnet-values.yaml b/library/ix-dev/community/pgadmin/ci/hostnet-values.yaml index 2cffccf830..c35de1e417 100644 --- a/library/ix-dev/community/pgadmin/ci/hostnet-values.yaml +++ b/library/ix-dev/community/pgadmin/ci/hostnet-values.yaml @@ -8,5 +8,4 @@ pgadminConfig: pgadminStorage: config: - type: hostPath - hostPath: /mnt/{{ .Release.Namespace }}/config + type: pvc diff --git a/library/ix-dev/community/pgadmin/ci/https-values.yaml b/library/ix-dev/community/pgadmin/ci/https-values.yaml index a7e49e0271..3489d2d6aa 100644 --- a/library/ix-dev/community/pgadmin/ci/https-values.yaml +++ b/library/ix-dev/community/pgadmin/ci/https-values.yaml @@ -5,8 +5,7 @@ pgadminNetwork: pgadminStorage: config: - type: hostPath - hostPath: /mnt/{{ .Release.Namespace }}/config + type: pvc pgadminConfig: adminEmail: some@email.com diff --git a/library/ix-dev/community/pgadmin/migrations/migrate b/library/ix-dev/community/pgadmin/migrations/migrate new file mode 100755 index 0000000000..77ea8cddd6 --- /dev/null +++ b/library/ix-dev/community/pgadmin/migrations/migrate @@ -0,0 +1,73 @@ +#!/usr/bin/python3 +import json +import os +import sys + + +def storage_migrate(storage): + delete_keys = [] + if storage['type'] == 'hostPath': + # Check if the key exists, if not we have already migrated + if not storage.get('hostPath'): + return storage + + storage['hostPathConfig'] = {'hostPath': storage['hostPath']} + delete_keys.append('hostPath') + + elif storage['type'] == 'ixVolume': + # Check if the key exists, if not we have already migrated + if not storage.get('datasetName'): + return storage + + storage['ixVolumeConfig'] = {'datasetName': storage['datasetName']} + delete_keys.append('datasetName') + + elif storage['type'] == 'smb-pv-pvc': + # Check if the key exists, if not we have already migrated + if not storage.get('server'): + return storage + + storage['smbConfig'] = { + 'server': storage['server'], + 'share': storage['share'], + 'domain': storage['domain'], + 'username': storage['username'], + 'password': storage['password'], + 'size': storage['size'], + } + delete_keys.extend(['server', 'share', 'domain', 'username', 'password', 'size']) + + for key in delete_keys: + storage.pop(key, None) + + return storage + + +def migrate(values): + storage_key = 'pgadminStorage' + storages = ['config'] + + for storage in storages: + check_val = values.get(storage_key, {}).get(storage, {}) + if not isinstance(check_val, dict) or not check_val: + raise Exception(f'Storage section {storage} is malformed') + + values[storage_key][storage] = storage_migrate(check_val) + + additionalStorages = values.get(storage_key, {}).get('additionalStorages', []) + for idx, storage in enumerate(additionalStorages): + if not isinstance(storage, dict) or not storage: + raise Exception(f'Item {idx} in additionalStorages is malformed') + + values[storage_key]['additionalStorages'][idx] = storage_migrate(storage) + + return values + + +if __name__ == '__main__': + if len(sys.argv) != 2: + exit(1) + + if os.path.exists(sys.argv[1]): + with open(sys.argv[1], 'r') as f: + print(json.dumps(migrate(json.loads(f.read())))) diff --git a/library/ix-dev/community/pgadmin/questions.yaml b/library/ix-dev/community/pgadmin/questions.yaml index ba91866349..3ac6c2c054 100644 --- a/library/ix-dev/community/pgadmin/questions.yaml +++ b/library/ix-dev/community/pgadmin/questions.yaml @@ -121,23 +121,64 @@ questions: description: Host Path (Path that already exists on the system) - value: "ixVolume" description: ixVolume (Dataset created automatically by the system) - - variable: datasetName - label: Dataset Name + - variable: ixVolumeConfig + label: ixVolume Configuration + description: The configuration for the ixVolume dataset. schema: - type: string + type: dict show_if: [["type", "=", "ixVolume"]] - required: true - hidden: true - immutable: true - default: "config" $ref: - "normalize/ixVolume" - - variable: hostPath - label: Host Path + attrs: + - variable: aclEnable + label: Enable ACL + description: Enable ACL for the dataset. + schema: + type: boolean + default: false + - variable: datasetName + label: Dataset Name + description: The name of the dataset to use for storage. + schema: + type: string + required: true + immutable: true + hidden: true + default: "config" + - variable: aclEntries + label: ACL Configuration + schema: + type: dict + show_if: [["aclEnable", "=", true]] + attrs: [] + - variable: hostPathConfig + label: Host Path Configuration schema: - type: hostpath + type: dict show_if: [["type", "=", "hostPath"]] - required: true + attrs: + - variable: aclEnable + label: Enable ACL + description: Enable ACL for the dataset. + schema: + type: boolean + default: false + - variable: acl + label: ACL Configuration + schema: + type: dict + show_if: [["aclEnable", "=", true]] + attrs: [] + $ref: + - "normalize/acl" + - variable: hostPath + label: Host Path + description: The host path to use for storage. + schema: + type: hostpath + show_if: [["aclEnable", "=", false]] + required: true + - variable: additionalStorages label: Additional Storage description: Additional storage for pgAdmin. @@ -168,74 +209,119 @@ questions: description: ixVolume (Dataset created automatically by the system) - value: "smb-pv-pvc" description: SMB Share (Mounts a persistent volume claim to a SMB share) + - variable: readOnly + label: Read Only + description: Mount the volume as read only. + schema: + type: boolean + default: false - variable: mountPath label: Mount Path description: The path inside the container to mount the storage. schema: type: path required: true - - variable: hostPath - label: Host Path - description: The host path to use for storage. + - variable: hostPathConfig + label: Host Path Configuration schema: - type: hostpath + type: dict show_if: [["type", "=", "hostPath"]] - required: true - - variable: datasetName - label: Dataset Name - description: The name of the dataset to use for storage. + attrs: + - variable: aclEnable + label: Enable ACL + description: Enable ACL for the dataset. + schema: + type: boolean + default: false + - variable: acl + label: ACL Configuration + schema: + type: dict + show_if: [["aclEnable", "=", true]] + attrs: [] + $ref: + - "normalize/acl" + - variable: hostPath + label: Host Path + description: The host path to use for storage. + schema: + type: hostpath + show_if: [["aclEnable", "=", false]] + required: true + - variable: ixVolumeConfig + label: ixVolume Configuration + description: The configuration for the ixVolume dataset. schema: - type: string + type: dict show_if: [["type", "=", "ixVolume"]] - required: true - immutable: true - default: "storage_entry" $ref: - "normalize/ixVolume" - - variable: server - label: Server - description: The server for the SMB share. + attrs: + - variable: aclEnable + label: Enable ACL + description: Enable ACL for the dataset. + schema: + type: boolean + default: false + - variable: datasetName + label: Dataset Name + description: The name of the dataset to use for storage. + schema: + type: string + required: true + immutable: true + default: "storage_entry" + - variable: aclEntries + label: ACL Configuration + schema: + type: dict + show_if: [["aclEnable", "=", true]] + attrs: [] + - variable: smbConfig + label: SMB Share Configuration + description: The configuration for the SMB Share. schema: - type: string + type: dict show_if: [["type", "=", "smb-pv-pvc"]] - required: true - - variable: share - label: Share - description: The share name for the SMB share. - schema: - type: string - show_if: [["type", "=", "smb-pv-pvc"]] - required: true - - variable: domain - label: Domain (Optional) - description: The domain for the SMB share. - schema: - type: string - show_if: [["type", "=", "smb-pv-pvc"]] - - variable: username - label: Username - description: The username for the SMB share. - schema: - type: string - show_if: [["type", "=", "smb-pv-pvc"]] - required: true - - variable: password - label: Password - description: The password for the SMB share. - schema: - type: string - show_if: [["type", "=", "smb-pv-pvc"]] - required: true - private: true - - variable: size - label: Size (in Gi) - description: The size of the volume quota. - schema: - type: int - show_if: [["type", "=", "smb-pv-pvc"]] - required: true - min: 1 - default: 1 + attrs: + - variable: server + label: Server + description: The server for the SMB share. + schema: + type: string + required: true + - variable: share + label: Share + description: The share name for the SMB share. + schema: + type: string + required: true + - variable: domain + label: Domain (Optional) + description: The domain for the SMB share. + schema: + type: string + - variable: username + label: Username + description: The username for the SMB share. + schema: + type: string + required: true + - variable: password + label: Password + description: The password for the SMB share. + schema: + type: string + required: true + private: true + - variable: size + label: Size (in Gi) + description: The size of the volume quota. + schema: + type: int + required: true + min: 1 + default: 1 - variable: resources group: Resources Configuration diff --git a/library/ix-dev/community/pgadmin/templates/_persistence.tpl b/library/ix-dev/community/pgadmin/templates/_persistence.tpl index e0f53c97af..b303981e52 100644 --- a/library/ix-dev/community/pgadmin/templates/_persistence.tpl +++ b/library/ix-dev/community/pgadmin/templates/_persistence.tpl @@ -2,15 +2,17 @@ persistence: config: enabled: true - type: {{ .Values.pgadminStorage.config.type }} - datasetName: {{ .Values.pgadminStorage.config.datasetName | default "" }} - hostPath: {{ .Values.pgadminStorage.config.hostPath | default "" }} + {{- include "pgadmin.storage.ci.migration" (dict "storage" .Values.pgadminStorage.config) }} + {{- include "ix.v1.common.app.storageOptions" (dict "storage" .Values.pgadminStorage.config) | nindent 4 }} targetSelector: pgadmin: pgadmin: mountPath: /var/lib/pgadmin + {{- if and (eq .Values.pgadminStorage.config.type "ixVolume") + (not (.Values.pgadminStorage.config.ixVolumeConfig | default dict).aclEnable) }} 01-permissions: mountPath: /mnt/directories/pgadmin + {{- end }} tmp: enabled: true type: emptyDir @@ -20,30 +22,17 @@ persistence: mountPath: /tmp {{- range $idx, $storage := .Values.pgadminStorage.additionalStorages }} {{ printf "pgadmin-%v" (int $idx) }}: - {{- $size := "" -}} - {{- if $storage.size -}} - {{- $size = (printf "%vGi" $storage.size) -}} - {{- end }} enabled: true - type: {{ $storage.type }} - datasetName: {{ $storage.datasetName | default "" }} - hostPath: {{ $storage.hostPath | default "" }} - server: {{ $storage.server | default "" }} - share: {{ $storage.share | default "" }} - domain: {{ $storage.domain | default "" }} - username: {{ $storage.username | default "" }} - password: {{ $storage.password | default "" }} - size: {{ $size }} - {{- if eq $storage.type "smb-pv-pvc" }} - mountOptions: - - key: noperm - {{- end }} + {{- include "pgadmin.storage.ci.migration" (dict "storage" $storage) }} + {{- include "ix.v1.common.app.storageOptions" (dict "storage" $storage) | nindent 4 }} targetSelector: pgadmin: pgadmin: mountPath: {{ $storage.mountPath }} + {{- if and (eq $storage.type "ixVolume") (not ($storage.ixVolumeConfig | default dict).aclEnable) }} 01-permissions: mountPath: /mnt/directories{{ $storage.mountPath }} + {{- end }} {{- end }} {{- if .Values.pgadminNetwork.certificateID }} @@ -69,3 +58,13 @@ scaleCertificate: id: {{ .Values.pgadminNetwork.certificateID }} {{- end }} {{- end -}} + +{{/* TODO: Remove on the next version bump, eg 1.2.0+ */}} +{{- define "pgadmin.storage.ci.migration" -}} + {{- $storage := .storage -}} + + {{- if $storage.hostPath -}} + {{- $_ := set $storage "hostPathConfig" dict -}} + {{- $_ := set $storage.hostPathConfig "hostPath" $storage.hostPath -}} + {{- end -}} +{{- end -}} diff --git a/library/ix-dev/community/pgadmin/templates/_pgadmin.tpl b/library/ix-dev/community/pgadmin/templates/_pgadmin.tpl index 9126e8d053..93e1561b49 100644 --- a/library/ix-dev/community/pgadmin/templates/_pgadmin.tpl +++ b/library/ix-dev/community/pgadmin/templates/_pgadmin.tpl @@ -60,5 +60,5 @@ workload: "UID" 5050 "GID" 5050 "mode" "check" - "type" "init") | nindent 8 }} + "type" "install") | nindent 8 }} {{- end -}} diff --git a/library/ix-dev/community/pgadmin/values.yaml b/library/ix-dev/community/pgadmin/values.yaml index 23f3145a0a..a5994a4bac 100644 --- a/library/ix-dev/community/pgadmin/values.yaml +++ b/library/ix-dev/community/pgadmin/values.yaml @@ -21,5 +21,6 @@ pgadminNetwork: pgadminStorage: config: type: ixVolume - datasetName: config + ixVolumeConfig: + datasetName: config additionalStorages: []