grafana - migrate storage (adds acls) (#1866)

* adapt ci values

* bump common and version

* update readme

* update values

* update template

* update questions

* add migration

* skip when acl are enabled

* typo

* adapt for helm 3.9.4

* one more
This commit is contained in:
Stavros Kois
2023-12-14 11:31:05 +02:00
committed by GitHub
parent a14c280278
commit 77b48b120b
14 changed files with 258 additions and 116 deletions

View File

@@ -1,6 +1,6 @@
dependencies:
- name: common
repository: file://../../../common
version: 1.2.3
digest: sha256:e6ff49b06bf5d4d159e505ae6d153f36cd46170bb519caf90462cd5caebfd0fb
generated: "2023-11-15T12:46:39.652341433+02:00"
version: 1.2.4
digest: sha256:47ebfd41bc2ac33ab6989e7bd4d1d3aea662365fffa8b525a24cc56a2a35c174
generated: "2023-12-13T15:31:53.4026267+02:00"

View File

@@ -4,7 +4,7 @@ description: Grafana is the open source analytics & monitoring solution for ever
annotations:
title: Grafana
type: application
version: 1.1.4
version: 1.2.0
apiVersion: v2
appVersion: 10.2.2
kubeVersion: '>=1.16.0-0'
@@ -15,7 +15,7 @@ maintainers:
dependencies:
- name: common
repository: file://../../../common
version: 1.2.3
version: 1.2.4
home: https://grafana.com
icon: https://media.sys.truenas.net/apps/grafana/icons/icon.png
sources:

View File

@@ -2,11 +2,6 @@
[Grafana](https://grafana.com/) is the open source analytics & monitoring solution for every database.
> When application is installed, a container will be launched with **root** privileges.
> This is required in order to apply the correct permissions to the `Grafana` directories.
> Afterward, the `Grafana` container will run as a **non**-root user (Default: `568`).
> All mounted storage(s) will be `chown`ed only if the parent directory does not match the configured user.
Additional configuration can be made by adding additional environment variables
Here is the available [configuration documentation](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/)

View File

@@ -2,11 +2,6 @@
[Grafana](https://grafana.com/) is the open source analytics & monitoring solution for every database.
> When application is installed, a container will be launched with **root** privileges.
> This is required in order to apply the correct permissions to the `Grafana` directories.
> Afterward, the `Grafana` container will run as a **non**-root user (Default: `568`).
> All mounted storage(s) will be `chown`ed only if the parent directory does not match the configured user.
Additional configuration can be made by adding additional environment variables
Here is the available [configuration documentation](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/)

View File

@@ -1,10 +1,8 @@
grafanaStorage:
data:
type: hostPath
hostPath: /mnt/{{ .Release.Name }}/data
type: pvc
additionalStorages:
- type: hostPath
hostPath: /mnt/{{ .Release.Namespace }}/logs
- type: pvc
mountPath: /logs
grafanaConfig:

View File

@@ -1,7 +1,6 @@
grafanaStorage:
data:
type: hostPath
hostPath: /mnt/{{ .Release.Name }}/data
type: pvc
grafanaRunAs:
user: 1000

View File

@@ -1,10 +1,8 @@
grafanaStorage:
data:
type: hostPath
hostPath: /mnt/{{ .Release.Name }}/data
type: pvc
additionalStorages:
- type: hostPath
hostPath: /mnt/{{ .Release.Namespace }}/logs
- type: pvc
mountPath: /logs
grafanaNetwork:

View File

@@ -1,7 +1,6 @@
grafanaStorage:
data:
type: hostPath
hostPath: /mnt/{{ .Release.Name }}/data
type: pvc
grafanaNetwork:
certificateID: 1

View File

@@ -0,0 +1,73 @@
#!/usr/bin/python3
import json
import os
import sys
def storage_migrate(storage):
delete_keys = []
if storage['type'] == 'hostPath':
# Check if the key exists, if not we have already migrated
if not storage.get('hostPath'):
return storage
storage['hostPathConfig'] = {'hostPath': storage['hostPath']}
delete_keys.append('hostPath')
elif storage['type'] == 'ixVolume':
# Check if the key exists, if not we have already migrated
if not storage.get('datasetName'):
return storage
storage['ixVolumeConfig'] = {'datasetName': storage['datasetName']}
delete_keys.append('datasetName')
elif storage['type'] == 'smb-pv-pvc':
# Check if the key exists, if not we have already migrated
if not storage.get('server'):
return storage
storage['smbConfig'] = {
'server': storage['server'],
'share': storage['share'],
'domain': storage['domain'],
'username': storage['username'],
'password': storage['password'],
'size': storage['size'],
}
delete_keys.extend(['server', 'share', 'domain', 'username', 'password', 'size'])
for key in delete_keys:
storage.pop(key, None)
return storage
def migrate(values):
storage_key = 'grafanaStorage'
storages = ['data']
for storage in storages:
check_val = values.get(storage_key, {}).get(storage, {})
if not isinstance(check_val, dict) or not check_val:
raise Exception(f'Storage section {storage} is malformed')
values[storage_key][storage] = storage_migrate(check_val)
additionalStorages = values.get(storage_key, {}).get('additionalStorages', [])
for idx, storage in enumerate(additionalStorages):
if not isinstance(storage, dict) or not storage:
raise Exception(f'Item {idx} in additionalStorages is malformed')
values[storage_key]['additionalStorages'][idx] = storage_migrate(storage)
return values
if __name__ == '__main__':
if len(sys.argv) != 2:
exit(1)
if os.path.exists(sys.argv[1]):
with open(sys.argv[1], 'r') as f:
print(json.dumps(migrate(json.loads(f.read()))))

View File

@@ -159,24 +159,64 @@ questions:
description: Host Path (Path that already exists on the system)
- value: "ixVolume"
description: ixVolume (Dataset created automatically by the system)
- variable: datasetName
label: Dataset Name
- variable: ixVolumeConfig
label: ixVolume Configuration
description: The configuration for the ixVolume dataset.
schema:
type: string
type: dict
show_if: [["type", "=", "ixVolume"]]
required: true
hidden: true
immutable: true
default: "data"
$ref:
- "normalize/ixVolume"
- variable: hostPath
label: Host Path
attrs:
- variable: aclEnable
label: Enable ACL
description: Enable ACL for the dataset.
schema:
type: boolean
default: false
- variable: datasetName
label: Dataset Name
description: The name of the dataset to use for storage.
schema:
type: string
required: true
immutable: true
hidden: true
default: "data"
- variable: aclEntries
label: ACL Configuration
schema:
type: dict
show_if: [["aclEnable", "=", true]]
attrs: []
- variable: hostPathConfig
label: Host Path Configuration
schema:
type: hostpath
type: dict
show_if: [["type", "=", "hostPath"]]
immutable: true
required: true
attrs:
- variable: aclEnable
label: Enable ACL
description: Enable ACL for the dataset.
schema:
type: boolean
default: false
- variable: acl
label: ACL Configuration
schema:
type: dict
show_if: [["aclEnable", "=", true]]
attrs: []
$ref:
- "normalize/acl"
- variable: hostPath
label: Host Path
description: The host path to use for storage.
schema:
type: hostpath
show_if: [["aclEnable", "=", false]]
required: true
- variable: additionalStorages
label: Additional Storage
description: Additional storage for Grafana.
@@ -207,74 +247,119 @@ questions:
description: ixVolume (Dataset created automatically by the system)
- value: "smb-pv-pvc"
description: SMB Share (Mounts a persistent volume claim to a SMB share)
- variable: readOnly
label: Read Only
description: Mount the volume as read only.
schema:
type: boolean
default: false
- variable: mountPath
label: Mount Path
description: The path inside the container to mount the storage.
schema:
type: path
required: true
- variable: hostPath
label: Host Path
description: The host path to use for storage.
- variable: hostPathConfig
label: Host Path Configuration
schema:
type: hostpath
type: dict
show_if: [["type", "=", "hostPath"]]
required: true
- variable: datasetName
label: Dataset Name
description: The name of the dataset to use for storage.
attrs:
- variable: aclEnable
label: Enable ACL
description: Enable ACL for the dataset.
schema:
type: boolean
default: false
- variable: acl
label: ACL Configuration
schema:
type: dict
show_if: [["aclEnable", "=", true]]
attrs: []
$ref:
- "normalize/acl"
- variable: hostPath
label: Host Path
description: The host path to use for storage.
schema:
type: hostpath
show_if: [["aclEnable", "=", false]]
required: true
- variable: ixVolumeConfig
label: ixVolume Configuration
description: The configuration for the ixVolume dataset.
schema:
type: string
type: dict
show_if: [["type", "=", "ixVolume"]]
required: true
immutable: true
default: "storage_entry"
$ref:
- "normalize/ixVolume"
- variable: server
label: Server
description: The server for the SMB share.
attrs:
- variable: aclEnable
label: Enable ACL
description: Enable ACL for the dataset.
schema:
type: boolean
default: false
- variable: datasetName
label: Dataset Name
description: The name of the dataset to use for storage.
schema:
type: string
required: true
immutable: true
default: "storage_entry"
- variable: aclEntries
label: ACL Configuration
schema:
type: dict
show_if: [["aclEnable", "=", true]]
attrs: []
- variable: smbConfig
label: SMB Share Configuration
description: The configuration for the SMB Share.
schema:
type: string
type: dict
show_if: [["type", "=", "smb-pv-pvc"]]
required: true
- variable: share
label: Share
description: The share name for the SMB share.
schema:
type: string
show_if: [["type", "=", "smb-pv-pvc"]]
required: true
- variable: domain
label: Domain (Optional)
description: The domain for the SMB share.
schema:
type: string
show_if: [["type", "=", "smb-pv-pvc"]]
- variable: username
label: Username
description: The username for the SMB share.
schema:
type: string
show_if: [["type", "=", "smb-pv-pvc"]]
required: true
- variable: password
label: Password
description: The password for the SMB share.
schema:
type: string
show_if: [["type", "=", "smb-pv-pvc"]]
required: true
private: true
- variable: size
label: Size (in Gi)
description: The size of the volume quota.
schema:
type: int
show_if: [["type", "=", "smb-pv-pvc"]]
required: true
min: 1
default: 1
attrs:
- variable: server
label: Server
description: The server for the SMB share.
schema:
type: string
required: true
- variable: share
label: Share
description: The share name for the SMB share.
schema:
type: string
required: true
- variable: domain
label: Domain (Optional)
description: The domain for the SMB share.
schema:
type: string
- variable: username
label: Username
description: The username for the SMB share.
schema:
type: string
required: true
- variable: password
label: Password
description: The password for the SMB share.
schema:
type: string
required: true
private: true
- variable: size
label: Size (in Gi)
description: The size of the volume quota.
schema:
type: int
required: true
min: 1
default: 1
- variable: resources
group: Resources Configuration

View File

@@ -49,7 +49,7 @@ workload:
"UID" .Values.grafanaRunAs.user
"GID" .Values.grafanaRunAs.group
"mode" "check"
"type" "init") | nindent 8 }}
"type" "install") | nindent 8 }}
{{/* Service */}}
service:
@@ -70,15 +70,17 @@ service:
persistence:
data:
enabled: true
type: {{ .Values.grafanaStorage.data.type }}
datasetName: {{ .Values.grafanaStorage.data.datasetName | default "" }}
hostPath: {{ .Values.grafanaStorage.data.hostPath | default "" }}
{{- include "grafana.storage.ci.migration" (dict "storage" .Values.grafanaStorage.data) }}
{{- include "ix.v1.common.app.storageOptions" (dict "storage" .Values.grafanaStorage.data) | nindent 4 }}
targetSelector:
grafana:
grafana:
mountPath: /var/lib/grafana
{{- if and (eq .Values.grafanaStorage.data.type "ixVolume")
(not (.Values.grafanaStorage.data.ixVolumeConfig | default dict).aclEnable) }}
01-permissions:
mountPath: /mnt/directories/data
{{- end }}
tmp:
enabled: true
type: emptyDir
@@ -87,31 +89,18 @@ persistence:
grafana:
mountPath: /tmp
{{- range $idx, $storage := .Values.grafanaStorage.additionalStorages }}
{{ printf "grafana-%v" (int $idx) }}:
{{- $size := "" -}}
{{- if $storage.size -}}
{{- $size = (printf "%vGi" $storage.size) -}}
{{- end }}
{{ printf "grafana-%v:" (int $idx) }}
enabled: true
type: {{ $storage.type }}
datasetName: {{ $storage.datasetName | default "" }}
hostPath: {{ $storage.hostPath | default "" }}
server: {{ $storage.server | default "" }}
share: {{ $storage.share | default "" }}
domain: {{ $storage.domain | default "" }}
username: {{ $storage.username | default "" }}
password: {{ $storage.password | default "" }}
size: {{ $size }}
{{- if eq $storage.type "smb-pv-pvc" }}
mountOptions:
- key: noperm
{{- end }}
{{- include "grafana.storage.ci.migration" (dict "storage" $storage) }}
{{- include "ix.v1.common.app.storageOptions" (dict "storage" $storage) | nindent 4 }}
targetSelector:
grafana:
grafana:
mountPath: {{ $storage.mountPath }}
{{- if and (eq $storage.type "ixVolume") (not ($storage.ixVolumeConfig | default dict).aclEnable) }}
01-permissions:
mountPath: /mnt/directories{{ $storage.mountPath }}
{{- end }}
{{- end }}
{{- if .Values.grafanaNetwork.certificateID }}
cert:
@@ -136,3 +125,13 @@ scaleCertificate:
id: {{ .Values.grafanaNetwork.certificateID }}
{{- end -}}
{{- end -}}
{{/* TODO: Remove on the next version bump, eg 1.2.0+ */}}
{{- define "grafana.storage.ci.migration" -}}
{{- $storage := .storage -}}
{{- if $storage.hostPath -}}
{{- $_ := set $storage "hostPathConfig" dict -}}
{{- $_ := set $storage.hostPathConfig "hostPath" $storage.hostPath -}}
{{- end -}}
{{- end -}}

View File

@@ -25,7 +25,8 @@ grafanaRunAs:
grafanaStorage:
data:
type: ixVolume
datasetName: data
ixVolumeConfig:
datasetName: data
additionalStorages: []
notes: