diff --git a/Makefile b/Makefile index 5dbe1af51..b9d8f1e42 100644 --- a/Makefile +++ b/Makefile @@ -31,12 +31,7 @@ prod: prod-build verify: fmt vet -godep-restore: check-gopath - godep restore - rm -rf vendor Godeps - -godep-save: check-gopath - godep save ./... +docs: _docs clean: rm -rf _docker_workspace @@ -118,3 +113,23 @@ reset-dev-patch: # Build devloper image dev: dev-patch prod-quick reset-dev-patch + +# Docs +# +doc-preview: + rm -rf docs/_build + DOCKER_RUN_ARGS="-p 127.0.0.1:8000:8000" \ + ./build-tools/docker-docs.sh make -C docs preview + +_docs: always-build + ./build-tools/docker-docs.sh ./build-tools/make-docs.sh + +docker-test: + rm -rf docs/_build + ./build-tools/docker-docs.sh ./build-tools/make-docs.sh + +# one-time html build using a docker container +.PHONY: docker-html +docker-html: + rm -rf docs/_build + ./build-tools/docker-docs.sh make -C docs/ html diff --git a/build-tools/Dockerfile.debian.runtime b/build-tools/Dockerfile.debian.runtime index 71dd233fe..ea0b59e50 100755 --- a/build-tools/Dockerfile.debian.runtime +++ b/build-tools/Dockerfile.debian.runtime @@ -21,7 +21,7 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ RUN apt-get remove -y libidn11 COPY bigip-virtual-server_v*.json $APPPATH/vendor/src/f5/schemas/ -COPY as3-schema-3.20.0-3-cis.json $APPPATH/vendor/src/f5/schemas/ +COPY as3-schema-3.21.0-4-cis.json $APPPATH/vendor/src/f5/schemas/ COPY k8s-bigip-ctlr $APPPATH/bin COPY VERSION_BUILD.json $APPPATH/vendor/src/f5/ diff --git a/build-tools/Dockerfile.debug.runtime b/build-tools/Dockerfile.debug.runtime index 1ef7a3844..6e7e74105 100644 --- a/build-tools/Dockerfile.debug.runtime +++ b/build-tools/Dockerfile.debug.runtime @@ -26,7 +26,7 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ RUN apt-get remove -y libidn11 COPY bigip-virtual-server_v*.json $APPPATH/vendor/src/f5/schemas/ -COPY as3-schema-3.20.0-3-cis.json $APPPATH/vendor/src/f5/schemas/ +COPY as3-schema-3.21.0-4-cis.json $APPPATH/vendor/src/f5/schemas/ COPY k8s-bigip-ctlr $APPPATH/bin COPY VERSION_BUILD.json $APPPATH/vendor/src/f5/ COPY --from=builder /go/bin/dlv /app/bin diff --git a/build-tools/Dockerfile.rhel7.runtime b/build-tools/Dockerfile.rhel7.runtime index 4a04f643e..52d72df0f 100644 --- a/build-tools/Dockerfile.rhel7.runtime +++ b/build-tools/Dockerfile.rhel7.runtime @@ -39,7 +39,7 @@ RUN microdnf --enablerepo=rhel-7-server-rpms --enablerepo=rhel-7-server-optional microdnf clean all COPY bigip-virtual-server_v*.json $APPPATH/vendor/src/f5/schemas/ -COPY as3-schema-3.20.0-3-cis.json $APPPATH/vendor/src/f5/schemas/ +COPY as3-schema-3.21.0-4-cis.json $APPPATH/vendor/src/f5/schemas/ COPY k8s-bigip-ctlr $APPPATH/bin/k8s-bigip-ctlr.real COPY VERSION_BUILD.json $APPPATH/vendor/src/f5/ diff --git a/build-tools/build-release-images.sh b/build-tools/build-release-images.sh index 0bbaf1f26..5b9e1fd8e 100755 --- a/build-tools/build-release-images.sh +++ b/build-tools/build-release-images.sh @@ -36,7 +36,7 @@ docker rm -f cp-temp cp requirements.txt $WKDIR/ cp schemas/bigip-virtual-server_v*.json $WKDIR/ -cp schemas/as3-schema-3.20.0-3-cis.json $WKDIR/ +cp schemas/as3-schema-3.21.0-4-cis.json $WKDIR/ cp LICENSE $WKDIR/ cp $CURDIR/help.md $WKDIR/help.md echo "{\"version\": \"${VERSION_INFO}\", \"build\": \"${BUILD_INFO}\"}" \ diff --git a/cmd/k8s-bigip-ctlr/main.go b/cmd/k8s-bigip-ctlr/main.go index 61fa51d1c..b7bc3ceef 100644 --- a/cmd/k8s-bigip-ctlr/main.go +++ b/cmd/k8s-bigip-ctlr/main.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -177,12 +177,12 @@ var ( ) func _init() { - flags = pflag.NewFlagSet("main", pflag.ContinueOnError) - globalFlags = pflag.NewFlagSet("Global", pflag.ContinueOnError) - bigIPFlags = pflag.NewFlagSet("BigIP", pflag.ContinueOnError) - kubeFlags = pflag.NewFlagSet("Kubernetes", pflag.ContinueOnError) - vxlanFlags = pflag.NewFlagSet("VXLAN", pflag.ContinueOnError) - osRouteFlags = pflag.NewFlagSet("OpenShift Routes", pflag.ContinueOnError) + flags = pflag.NewFlagSet("main", pflag.PanicOnError) + globalFlags = pflag.NewFlagSet("Global", pflag.PanicOnError) + bigIPFlags = pflag.NewFlagSet("BigIP", pflag.PanicOnError) + kubeFlags = pflag.NewFlagSet("Kubernetes", pflag.PanicOnError) + vxlanFlags = pflag.NewFlagSet("VXLAN", pflag.PanicOnError) + osRouteFlags = pflag.NewFlagSet("OpenShift Routes", pflag.PanicOnError) // Flag wrapping var err error @@ -692,6 +692,11 @@ func initCustomResourceManager( } func main() { + defer func() { + if r := recover(); r != nil { + flags.Usage() + } + }() err := flags.Parse(os.Args) if nil != err { os.Exit(1) diff --git a/cmd/k8s-bigip-ctlr/main_test.go b/cmd/k8s-bigip-ctlr/main_test.go index 145031472..c3e31aefb 100644 --- a/cmd/k8s-bigip-ctlr/main_test.go +++ b/cmd/k8s-bigip-ctlr/main_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -595,16 +595,18 @@ var _ = Describe("Main Tests", func() { } flags.SetOutput(MockOut{}) + defer func() { + Expect(called).To(BeTrue()) + }() defer flags.SetOutput(os.Stderr) - + defer func() { + if r := recover(); r != nil { + flags.Usage() + } + }() err := flags.Parse(os.Args) Expect(err).ToNot(BeNil()) - // This implementation changed in spf13 v1.0.3. - // Usage() is not called as ContinueOnError is set for unit tests. - // So we adopted to the new behaviour introduced. - // Refer --> FlagSet.failf() in flag.go - Expect(called).To(BeFalse()) - Expect(len(*openshiftSDNName)).To(Equal(0)) + }) It("sets up watches for all namespaces", func() { diff --git a/cmd/k8s-bigip-ctlr/pythonDriver.go b/cmd/k8s-bigip-ctlr/pythonDriver.go index 4e7474460..03ce232a1 100644 --- a/cmd/k8s-bigip-ctlr/pythonDriver.go +++ b/cmd/k8s-bigip-ctlr/pythonDriver.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2019, F5 Networks, Inc. + * Copyright (c) 2019-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/docs/README.rst b/docs/README.rst index a560f4251..c8877b45b 100644 --- a/docs/README.rst +++ b/docs/README.rst @@ -125,7 +125,7 @@ General .. note:: - - The :code:`python-basedir` setting lets you specify the path to an alternate python agent that can bridge between the |kctlr| and `F5 CCCL `_. + - The :code:`python-basedir` setting lets you specify the path to an alternate python agent that can bridge between the |kctlr| and F5-CCCL. - The time it takes for the |kctlr| to reapply the system configurations to the BIG-IP device is normally low (a few ms) and won't cause service disruption. @@ -359,7 +359,7 @@ See the `Integration Overview`_ for more information about F5 resources. | f5type | Tells ``k8s-bigip-ctlr`` about resources it | | | | should watch | | +---------------+---------------------------------------------------+-----------------------------------------------+ -| schema | Verifies the ``data`` blob | See the `F5 schema versions`_ table | +| schema | Verifies the ``data`` blob | See the F5 schema versions table | +---------------+---------------------------------------------------+-----------------------------------------------+ | data | Defines the F5 resource | | +---------------+---------------------------------------------------+-----------------------------------------------+ @@ -379,7 +379,7 @@ The `F5 schema`_ allows the |kctlr| to communicate with BIG-IP systems. While all versions of the BIG-IP Controller and F5 schema are backwards-compatible, using an older schema may limit Controller functionality. Be sure to use the schema version that corresponds with your Controller version to ensure access to the full feature set. - See the `F5 schema versions`_ table for schema and Controller version compatibility. + See the F5 schema versions table for schema and Controller version compatibility. .. _frontend: @@ -434,11 +434,11 @@ sslProfile [#ssl]_ JSON object Optional BIG-IP S .. note:: - If you include ``virtualAddress`` in your Resource definition, you can specify the ``bindAddr`` and ``port`` you want the virtual server to use. Omit the ``virtualAddress`` section if you want to create `pools without virtual servers`_. + If you include ``virtualAddress`` in your Resource definition, you can specify the ``bindAddr`` and ``port`` you want the virtual server to use. Omit the ``virtualAddress`` section if you want to create pools without virtual servers. If you're creating pools without virtual servers, **you should already have a BIG-IP virtual server** that handles client connections configured with an iRule or local traffic policy that can forward requests to the correct pool for the Service. - You can also `assign IP addresses to BIG-IP virtual servers using IPAM`_. + You can also assign IP addresses to BIG-IP virtual servers using IPAM. .. _iapp f5 resource: @@ -800,29 +800,29 @@ Example Configuration Files - :fonticon:`fa fa-download` :download:`example-vs-resource.json ` - :fonticon:`fa fa-download` :download:`example-vs-resource-iapp.json ` - :fonticon:`fa fa-download` :download:`example-advanced-vs-resource-iapp.json ` -- :fonticon:`fa fa-download` :download:`single-service-ingress.yaml ` -- :fonticon:`fa fa-download` :download:`single-service-tls-ingress.yaml ` -- :fonticon:`fa fa-download` :download:`simple-ingress-fanout.yaml ` -- :fonticon:`fa fa-download` :download:`name-based-ingress.yaml ` -- :fonticon:`fa fa-download` :download:`ingress-with-health-monitors.yaml ` +- :fonticon:`fa fa-download` :download:`single-service-ingress.yaml ` +- :fonticon:`fa fa-download` :download:`single-service-tls-ingress.yaml ` +- :fonticon:`fa fa-download` :download:`simple-ingress-fanout.yaml ` +- :fonticon:`fa fa-download` :download:`name-based-ingress.yaml ` +- :fonticon:`fa fa-download` :download:`ingress-with-health-monitors.yaml ` - :fonticon:`fa fa-download` :download:`sample-rbac.yaml ` -- :fonticon:`fa fa-download` :download:`sample-app-root-annotation.yaml ` -- :fonticon:`fa fa-download` :download:`sample-url-rewrite-annotation.yaml ` +- :fonticon:`fa fa-download` :download:`sample-app-root-annotation.yaml ` +- :fonticon:`fa fa-download` :download:`sample-url-rewrite-annotation.yaml ` OpenShift ````````` -- :fonticon:`fa fa-download` :download:`sample-unsecured-route.yaml ` -- :fonticon:`fa fa-download` :download:`sample-edge-route.yaml ` -- :fonticon:`fa fa-download` :download:`sample-passthrough-route.yaml ` -- :fonticon:`fa fa-download` :download:`sample-reencrypt-route.yaml ` +- :fonticon:`fa fa-download` :download:`sample-unsecured-route.yaml ` +- :fonticon:`fa fa-download` :download:`sample-edge-route.yaml ` +- :fonticon:`fa fa-download` :download:`sample-passthrough-route.yaml ` +- :fonticon:`fa fa-download` :download:`sample-reencrypt-route.yaml ` .. rubric:: **Footnotes** .. [#objectpartition] The |kctlr| creates and manages objects in the BIG-IP partition defined in the `F5 resource`_ ConfigMap. **It cannot manage objects in the** ``/Common`` **partition**. .. [#nodeportmode] The |kctlr| forwards traffic to the NodePort assigned to the Service by Kubernetes. See the `Kubernetes Service`_ documentation for more information. -.. [#lb] The |kctlr| supports BIG-IP load balancing algorithms that do not require additional configuration parameters. You can view the full list of supported algorithms in the `f5-cccl schema `_. See the `BIG-IP Local Traffic Management Basics user guide `_ for information about each load balancing mode. +.. [#lb] The |kctlr| supports BIG-IP load balancing algorithms that do not require additional configuration parameters. You can view the full list of supported algorithms in the f5-cccl schema. See the `BIG-IP Local Traffic Management Basics user guide `_ for information about each load balancing mode. .. [#ba] The Controller supports BIG-IP `route domain`_ specific addresses. .. [#ssl] If you want to configure multiple SSL profiles, use ``f5ProfileNames`` instead of ``f5ProfileName``. The two parameters are mutually exclusive. .. [#hm1] Required if defining the ``virtual-server.f5.com/health`` Ingress/Route annotation. diff --git a/docs/RELEASE-NOTES.rst b/docs/RELEASE-NOTES.rst index ffacbba54..91ceed1a3 100644 --- a/docs/RELEASE-NOTES.rst +++ b/docs/RELEASE-NOTES.rst @@ -1,11 +1,40 @@ Release Notes for Container Ingress Services for Kubernetes & OpenShift ======================================================================= -Next Release ------------- +2.1.1 +------------- +Added Functionality +````````````````````` +* CIS is now compatible with: + - OpenShift 4.5. + - AS3 3.21. +* Custom Resource Definition (CRD) – Preview version available with `virtual-server` and `TLSProfile` custom resources. + - `CRD Doc and Examples `_. +* Custom Resource Definition (CRD) – Added Support for k8s Secrets with TLSProfile Custom Resource. +* Custom Resource Definition (CRD) – Improved the strategy of processing `virtual-server` and `TLSProfile` custom resources. +* Custom Resource Definition (CRD) – Added support for installation using Helm and Operator. +* Custom Resource Definition (CRD) – Streamlined logs to provide insightful information in INFO and remove unwanted information in DEBUG mode. Bug Fixes ````````` +* :issues:`1467` AS3 ERROR declaration.schemaVersion must be one of the following with Controller version 2.1.0. +* :issues:`1433` Template is not valid. When using CIS 2.1 with AS3 version: 3.21.0. +* :issues:`1440` Optional health check parameters don't appear to be optional. +* Fixed issues with processing multiple services with same annotations in AS3 ConfigMap mode. + - When there are multiple services with same annotations, CIS updates the oldest service endpoints in BIG-IP. +* Fixed issues with continuous AS3 declarations in CRD mode. +* Fixed issues with re-encrypt termination on multiple domains in CRD mode. +* Fixed issues with crashing of CIS in CRD mode. + - When user removes f5cr label from `VirtualServer` or `TLSProfile` custom resources. + - When user deletes `TLSProfile` custom resource. This behaviour is intermittent. +* Fixed issues with processing of unwanted endpoint and service changes in CRD mode. + +Limitations +``````````` +* During restarts, CIS fails to read `TLSProfile` custom resource. This behaviour is intermittent. +* CIS does not update the endpoint changes on BIG-IP in CRD mode. This behaviour is intermittent. +* CIS does not validate secrets and BIG-IP profiles provided in `TLSProfile` custom resource. +* CIS supports only port 80 and 443 for BIG-IP Virtual servers in CRD mode. 2.1 ------------- @@ -13,9 +42,9 @@ Added Functionality ``````````````````` * CIS will not create `_AS3` partition anymore. - CIS uses single partition(i.e. `--bigip-partition`) to configure both LTM and NET configuration. - - Additional AS3 managed partition _AS3 will be removed if exists. + - Removes Additional AS3 managed partition _AS3, if exists. * Enhanced performance for lower BIG-IP CPU Utilization with optimized CCCL calls. -* AS3 versions >= 3.18 required for CIS 2.x releases. +* CIS 2.x releases requires AS3 versions >= 3.18. * CIS is now compatible with: - OpenShift 4.4.5. - AS3 3.20. @@ -58,7 +87,7 @@ Vulnerability Fixes Archived CF and Mesos Github repos `````````````````````````````````` -* These GitHub repository has been archived and is read-only. This projects are no longer actively maintained +* This projects are no longer actively maintained - `cf-bigip-ctlr `_ - `marathon-bigip-ctlr `_ @@ -68,7 +97,7 @@ Guidelines for upgrading to CIS 2.1 - User should clean up LTM resources in BIG-IP partition created by CCCL before migrating to CIS 2.1. Steps to clean up LTM resources in BIG-IP partition using AS3 * Use below POST call along with this `AS3 declaration `_. - - https:///mgmt/shared/appsvcs/declare?async=true + - mgmt/shared/appsvcs/declare * Note: Please modify in above POST call and name in `AS3 declaration `_ 2.0 @@ -81,7 +110,7 @@ Added Functionality * Added new optional deployment arguments: - `--custom-resource-mode` (default `false`) when set `true` processes custom resources only. - `defined-as3-declaration` for processing user defined AS3 Config Map in CIS watched namespaces. -* AS3 versions >= 3.18 is required for 2.x releases. +* CIS Requires AS3 versions >= 3.18 for 2.x releases. * CIS is now compatible with: - OpenShift 4.3. - BIG-IP 15.1. @@ -117,11 +146,11 @@ Vulnerability Fixes Limitations ``````````` -* CIS with cccl as agent, OpenShift A/B route cannot be updated in BIGIP >=v14.1.x due to data group changes. +* CIS in cccl mode, cannot update OpenShift A/B route in BIGIP >=v14.1.x due to data group changes. Next Upgrade Notes `````````````````` -* From CIS 2.1, additional AS3 managed partition "_AS3" will be removed. +* CIS removes additional AS3 managed partition "_AS3" from release 2.1 1.14.0 ------------ @@ -429,7 +458,7 @@ Bug Fixes Limitations ``````````` -* Cannot apply app-root and url-rewrite annotations to the same resource; see: :issues:`675` +* Cannot apply app-root and url-rewrite annotations to the same resource; see: :issues:675 * If an older controller created resources, upgrading to the new version could result in a python exception when adding metadata to virtuals: :issues:`683` * If running the controller in cluster mode without a vxlan name, pool members are not created: :issues:`686` @@ -439,21 +468,21 @@ v1.4.2 Bug Fixes ````````` -* :issues:`549` - Using IP annotation on ConfigMaps would result in the virtual server getting a port of 0. -* :issues:`551` - Memory leak in python subprocess -* :cccl-issue:`211` - Memory leak in f5-cccl submodule -* :issues:`555` - Controller high CPU usage when inactive -* :issues:`510` - Change behavior of controller on startup when encountering errors -* :issues:`567` - Clean up all objects (including iRules and datagroups) when deleting Routes. +* :issues:549 - Using IP annotation on ConfigMaps would result in the virtual server getting a port of 0. +* :issues:551 - Memory leak in python subprocess +* :cccl-issue:211 - Memory leak in f5-cccl submodule +* :issues:555 - Controller high CPU usage when inactive +* :issues:510 - Change behavior of controller on startup when encountering errors +* :issues:567 - Clean up all objects (including iRules and datagroups) when deleting Routes. v1.4.1 ------ Bug Fixes ````````` -* :issues:`517` - Controller deletes SSL profiles off of Ingress virtual servers if watching multiple namespaces. -* :issues:`471` - When updating routes, old service pools are not removed until after a refresh cycle. -* :cccl-issue:`208` - Address compatibility for BIG-IP v13.0 Health Monitor interval and timeout. +* (github-517)Controller deletes SSL profiles off of Ingress virtual servers if watching multiple namespaces. +* (github-471)When updating routes, old service pools are not removed until after a refresh cycle. +* (github-228)Address compatibility for BIG-IP v13.0 Health Monitor interval and timeout. v1.4.0 ------ @@ -479,12 +508,12 @@ Added Functionality Bug Fixes ````````` -* :issues:`341` - HTTPS redirect applies to individual Routes instead of all Routes. -* :issues:`344` - Create default for SNI profile when using Ingress custom profiles from Secrets. -* :issues:`460` - Remove risk that pools will update with wrong members after a node update (NodePort mode). -* :issues:`428` - Controller writes unnecessary updates when no config changes occurred. -* :issues:`506` - Controller stops updating BIG-IP after an exception occurs in the python driver. -* :cccl-issue:`198` - Corrected a comparison problem in CCCL that caused unnecessary updates for BIG-IP Virtual Server resources. +* (github-341)HTTPS redirect applies to individual Routes instead of all Routes. +* (github-344)Create default for SNI profile when using Ingress custom profiles from Secrets. +* (github-460)Remove risk that pools will update with wrong members after a node update (NodePort mode). +* (github-428)Controller writes unnecessary updates when no config changes occurred. +* (github-506)Controller stops updating BIG-IP after an exception occurs in the python driver. +* (github-198)Corrected a comparison problem in CCCL that caused unnecessary updates for BIG-IP Virtual Server resources. Limitations ``````````` @@ -499,7 +528,7 @@ Limitations - `Download and install the latest iApps templates`_. - `Set the service to use the newer iApp template`_. -* Check BIG-IP version compatibility on Application Services (iApps) before deploying. See Application Services Integration iApp `[#16] `_ for more information. +* Check BIG-IP version compatibility on Application Services (iApps) before deploying. See Application Services Integration iApp. * Cannot delete ARP entries on BIG-IP v11.6.1 when running the Controller in Kubernetes with Flannel VXLAN enabled. * The controller will exit at startup if it cannot establish a connection with the BIG-IP. @@ -553,17 +582,16 @@ Bug Fixes Limitations ``````````` -* OpenShift - Does not currently support redirect for individual Routes. If a Route specifies +* OpenShift - (github-341)Does not currently support redirect for individual Routes. If a Route specifies "insecureEdgeTerminationPolicy" as "Redirect", the http virtual server will enable this policy for all Routes. - `[#341] `_ v1.1.1 ------ Bug Fixes ````````` -* Fix SIGSEV on non-"f5" valued class annotation `[#311] `_ -* Remove default pool for Ingress and Routes `[#288] `_ +* (github-311)Fix SIGSEV on non-"f5" valued class annotation. +* (github-288)Remove default pool for Ingress and Routes. v1.1.0 ------ @@ -623,4 +651,4 @@ Limitations .. _Download and install the latest iApps templates: https://support.f5.com/csp/article/K13422 -.. _Set the service to use the newer iApp template: https://support.f5.com/csp/article/K17001 +.. _Set the service to use the newer iApp template: https://support.f5.com/csp/article/K17001 \ No newline at end of file diff --git a/docs/_static/config_examples/crd/CustomResource.md b/docs/_static/config_examples/crd/CustomResource.md index 47d18dcc4..f8439a3ca 100644 --- a/docs/_static/config_examples/crd/CustomResource.md +++ b/docs/_static/config_examples/crd/CustomResource.md @@ -1,4 +1,4 @@ -# Container Ingress Services using Virtual Server Custom Resource +# Custom Resource Definitions This page is created to document the behaviour of CIS in CRD Mode(ALPHA Release). This is an ALPHA release which supports limited features. Check for the Supported Features and TO BE Implemented sections to understand in detail about the features. @@ -13,7 +13,7 @@ This page is created to document the behaviour of CIS in CRD Mode(ALPHA Release) * CIS supports 2 Custom Resources at this point of time. - VirtualServer - TLSProfile - + ## VirtualServer * VirtualServer resource defines load balancing configuration for a domain name. @@ -33,6 +33,13 @@ This page is created to document the behaviour of CIS in CRD Mode(ALPHA Release) servicePort: 80 ``` +## Label +* CIS will only process custom resources with f5cr Label as true. +``` + labels: + f5cr: "true" +``` + **Note: The above VirtualServer is insecure, Attach a TLSProfile to make it secure** ## TLSProfile @@ -84,6 +91,7 @@ This page is created to document the behaviour of CIS in CRD Mode(ALPHA Release) different terminations(for same domain), one with edge and another with re-encrypt. Todo this he needs to create two VirtualServers one with edge TLSProfile and another with re-encrypt TLSProfile. - Both the VirutalServers should be created with same virtualServerAddress * Single or Group of VirtualServers(with same virtualServerAddress) will be created as one common BIG-IP-VirtualServer. +* If user want to update secure virtual (TLS Virtual) server to insecure virtual (non-TLS server) server. User needs to delete the secure virtual server first and create a new virtual server. ## How CIS works with CRDs @@ -100,7 +108,8 @@ different terminations(for same domain), one with edge and another with re-encry # VirtualServer * Schema Validation - OpenAPI Schema Validation - https://raw.githubusercontent.com/F5Networks/k8s-bigip-ctlr/master/docs/_static/config_examples/crd/basic/vs-customresourcedefinitions.yml + + https://raw.githubusercontent.com/F5Networks/k8s-bigip-ctlr/master/docs/_static/config_examples/crd/basic/vs-customresourcedefinition.yml **VirtualServer Components** @@ -132,10 +141,13 @@ different terminations(for same domain), one with edge and another with re-encry | interval | Int | required | 5 | Seconds between health queries | | timeout | Int | Optional | 16 | Seconds before query fails | + **Note: Health Monitor associated with the first path will be considere if multiple path has same backend** + ## TLSProfile * Schema Validation - OpenAPI Schema Validation - https://raw.githubusercontent.com/F5Networks/k8s-bigip-ctlr/master/docs/_static/config_examples/crd/tls/tls-customresourcedefinitions.yml + + https://raw.githubusercontent.com/F5Networks/k8s-bigip-ctlr/master/docs/_static/config_examples/crd/tls/tls-customresourcedefinition.yml **TLSProfile Components** @@ -203,8 +215,11 @@ kubectl create -f sample-nodeport-k8s-bigip-ctlr-crd-secret.yml [-n kube-system] kubectl create -f sample-cluster-k8s-bigip-ctlr-crd-secret.yml [-n kube-system] ``` +## Examples + + https://github.com/F5Networks/k8s-bigip-ctlr/tree/master/docs/_static/config_examples/crd + ## To Be Implemented -* TLSProfile Support with k8s secrets * A/B Deployment * Support for WAF * Rewrite Rules @@ -212,5 +227,5 @@ kubectl create -f sample-cluster-k8s-bigip-ctlr-crd-secret.yml [-n kube-system] ## Note * “--custom-resource-mode=true” deploys CIS in Custom Resource Mode. -* CIS does not watch for ingress/routes when deployed in CRD Mode. -* CIS does not support combination of CRDs with any of Ingress/Routes or Configmaps. \ No newline at end of file +* CIS does not watch for ingress/routes/configmaps when deployed in CRD Mode. +* CIS does not support combination of CRDs with any of Ingress/Routes and Configmaps. \ No newline at end of file diff --git a/docs/_static/config_examples/crd/Install/README.md b/docs/_static/config_examples/crd/Install/README.md new file mode 100644 index 000000000..9c6d5e1ce --- /dev/null +++ b/docs/_static/config_examples/crd/Install/README.md @@ -0,0 +1,3 @@ +# Installation + +This section demonstrates the Installation of CIS in CRD Mode. \ No newline at end of file diff --git a/docs/_static/config_examples/crd/Install/customresourcedefinitions.yml b/docs/_static/config_examples/crd/Install/customresourcedefinitions.yml index a0aaa02f4..85f826191 100644 --- a/docs/_static/config_examples/crd/Install/customresourcedefinitions.yml +++ b/docs/_static/config_examples/crd/Install/customresourcedefinitions.yml @@ -28,6 +28,8 @@ spec: pattern: '^(([a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9\-]*[a-zA-Z0-9])\.)*([A-Za-z0-9]|[A-Za-z0-9][A-Za-z0-9\-]*[A-Za-z0-9])$' httpTraffic: type: string + tlsProfileName: + type: string pools: type: array items: @@ -60,6 +62,10 @@ spec: type: integer timeout: type: integer + required: + - type + - send + - interval virtualServerAddress: type: string pattern: '^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])$' @@ -110,4 +116,4 @@ spec: reference: type: string required: - - clientSSL \ No newline at end of file + - clientSSL diff --git a/docs/_static/config_examples/crd/basic/README.md b/docs/_static/config_examples/crd/basic/README.md new file mode 100644 index 000000000..a2e967307 --- /dev/null +++ b/docs/_static/config_examples/crd/basic/README.md @@ -0,0 +1,13 @@ +# UnSecure Virtual Server + +This section demonstrates the deployment of unsecured Virtual Servers. + +## example-single-pool-virtual.yaml + +By deploying this yaml file in your cluster, CIS will create a Virtual Server on BIG-IP with VIP "172.16.3.4". +It will load balance the traffic for domain cafe.example.com + +## example-two-pool-two-virtual.yaml + +By deploying this yaml file in your cluster, CIS will create two Virtual Servers on BIG-IP with VIP "172.16.3.4" and "172.16.3.5". +Former will load balance the traffic for domain coffee.example.com and later will load balance the traffic for domain tea-virtual-server diff --git a/docs/_static/config_examples/crd/basic/example-single-pool-virtual.yml b/docs/_static/config_examples/crd/basic/example-single-pool-virtual.yaml similarity index 66% rename from docs/_static/config_examples/crd/basic/example-single-pool-virtual.yml rename to docs/_static/config_examples/crd/basic/example-single-pool-virtual.yaml index 5206274e5..826fc68fa 100644 --- a/docs/_static/config_examples/crd/basic/example-single-pool-virtual.yml +++ b/docs/_static/config_examples/crd/basic/example-single-pool-virtual.yaml @@ -5,6 +5,8 @@ metadata: labels: f5cr: "true" spec: + # This is an insecure virtual, Please use TLSProfile to secure the virtual + # check out tls examples to understand more. host: cafe.example.com virtualServerAddress: "172.16.3.4" pools: diff --git a/docs/_static/config_examples/crd/basic/example-two-pool-two-virtual.yaml b/docs/_static/config_examples/crd/basic/example-two-pool-two-virtual.yaml index 9ff5c2beb..bf28e4c28 100644 --- a/docs/_static/config_examples/crd/basic/example-two-pool-two-virtual.yaml +++ b/docs/_static/config_examples/crd/basic/example-two-pool-two-virtual.yaml @@ -5,6 +5,8 @@ metadata: labels: f5cr: "true" spec: + # This is an insecure virtual, Please use TLSProfile to secure the virtual + # check out tls examples to understand more. virtualServerAddress: "172.16.3.4" host: coffee.example.com pools: @@ -23,6 +25,8 @@ metadata: labels: f5cr: "true" spec: + # This is an insecure virtual, Please use TLSProfile to secure the virtual + # check out tls examples to understand more. virtualServerAddress: "172.16.3.5" host: tea.example.com pools: diff --git a/docs/_static/config_examples/crd/basic/vs-customresourcedefinition.yml b/docs/_static/config_examples/crd/basic/vs-customresourcedefinition.yml index 0c79e0aa7..84c9e3764 100644 --- a/docs/_static/config_examples/crd/basic/vs-customresourcedefinition.yml +++ b/docs/_static/config_examples/crd/basic/vs-customresourcedefinition.yml @@ -60,6 +60,10 @@ spec: type: integer timeout: type: integer + required: + - type + - send + - interval virtualServerAddress: type: string pattern: '^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])$' diff --git a/docs/_static/config_examples/crd/tls/README.md b/docs/_static/config_examples/crd/tls/README.md new file mode 100644 index 000000000..7a5c5d781 --- /dev/null +++ b/docs/_static/config_examples/crd/tls/README.md @@ -0,0 +1,3 @@ +# Various TLS Configurations + +This section demonstrates various examples of securing Virtual Servers with TLSProfiles. \ No newline at end of file diff --git a/docs/_static/config_examples/crd/tls/reencrypt-bigip-reference/README.md b/docs/_static/config_examples/crd/tls/reencrypt-bigip-reference/README.md new file mode 100644 index 000000000..d3ab8fe17 --- /dev/null +++ b/docs/_static/config_examples/crd/tls/reencrypt-bigip-reference/README.md @@ -0,0 +1,13 @@ +# Secure Virtual Server with Re-encrypt Termination using BIG-IP Profiles + +This section demonstrates the deployment of a Secure Virtual Server with Re-encrypt Termination using BIG-IP Profiles. + +## virtualserver.yml + +By deploying this yaml file in your cluster, CIS will create a Virtual Server on BIG-IP with VIP "172.16.3.5". +It will load balance the traffic for domain coffee.example.com + +## reencrypt-tls.yml + +By deploying this yaml file in your cluster, CIS will attach /Common/clientssl as clientssl and /Common/serverssl as serverssl +for above Virtual Server with VIP "172.16.3.5". \ No newline at end of file diff --git a/docs/_static/config_examples/crd/tls/tls/reencrypt-tls.yml b/docs/_static/config_examples/crd/tls/reencrypt-bigip-reference/reencrypt-tls.yml similarity index 65% rename from docs/_static/config_examples/crd/tls/tls/reencrypt-tls.yml rename to docs/_static/config_examples/crd/tls/reencrypt-bigip-reference/reencrypt-tls.yml index c89b90fe1..5c9e81a1b 100644 --- a/docs/_static/config_examples/crd/tls/tls/reencrypt-tls.yml +++ b/docs/_static/config_examples/crd/tls/reencrypt-bigip-reference/reencrypt-tls.yml @@ -7,8 +7,8 @@ metadata: spec: tls: termination: reencrypt - clientSSL: /common/clientssl - serverSSL: /common/serverssl + clientSSL: /Common/clientssl + serverSSL: /Common/serverssl reference: bigip hosts: - - coffee.example.com \ No newline at end of file + - coffee.example.com diff --git a/docs/_static/config_examples/crd/tls/tls/virtualserver.yml b/docs/_static/config_examples/crd/tls/reencrypt-bigip-reference/virtualserver.yml similarity index 100% rename from docs/_static/config_examples/crd/tls/tls/virtualserver.yml rename to docs/_static/config_examples/crd/tls/reencrypt-bigip-reference/virtualserver.yml diff --git a/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/README.md b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/README.md new file mode 100644 index 000000000..b641fe370 --- /dev/null +++ b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/README.md @@ -0,0 +1,29 @@ +# Single Domain with combination of Edge and Re-encrypt termination + +This section demonstrates the deployment of two Virtual Servers one with Edge Termination and other with Re-encrypt Termination. +Both the Virtual Servers refer same domain[tea.example.com]. + +## tea-virtual-server_edge.yml + +By deploying this yaml file in your cluster, CIS will create a Virtual Server on BIG-IP with VIP "172.16.3.4". +It will load balance the traffic for service svc-edge on domain tea.example.com + +## tea-virtual-server_reen.yml + +By deploying this yaml file in your cluster, CIS will update Virtual Server on BIG-IP with VIP "172.16.3.4". +It will load balance the traffic for service svc-1 and svc-2 on domain tea.example.com + +## reencrypt-tls.yml + +By deploying this yaml file in your cluster, CIS will attach k8s secrets[clientssl and serverssl] as client and server +profiles for VIP "172.16.3.4". + +This is only applicable for services svc-1 and svc-2 + +## edge-tls.yml + +By deploying this yaml file in your cluster, CIS will attach k8s secret[clientssl] as client profile for VIP "172.16.3.4". + +This is only applicable for services svc-edge + +## Note: clientssl mentioned in both edge-tls.yml and reencrypt-tls.yml should be same as both are pointing to same domain. \ No newline at end of file diff --git a/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/edge-tls.yaml b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/edge-tls.yaml new file mode 100644 index 000000000..3297556c4 --- /dev/null +++ b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/edge-tls.yaml @@ -0,0 +1,14 @@ +apiVersion: cis.f5.com/v1 +kind: TLSProfile +metadata: + labels: + f5cr: "true" + name: edge-tls + namespace: default +spec: + hosts: + - tea.example.com + tls: + clientSSL: clientssl + reference: secret + termination: edge \ No newline at end of file diff --git a/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/reencrypt-tls.yml b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/reencrypt-tls.yml new file mode 100644 index 000000000..32c3261cd --- /dev/null +++ b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/reencrypt-tls.yml @@ -0,0 +1,14 @@ +apiVersion: cis.f5.com/v1 +kind: TLSProfile +metadata: + name: reencrypt-tls + labels: + f5cr: "true" +spec: + tls: + termination: reencrypt + clientSSL: clientssl + serverSSL: serverssl + reference: secret + hosts: + - tea.example.com \ No newline at end of file diff --git a/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/tea-virtual-server_edge.yaml b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/tea-virtual-server_edge.yaml new file mode 100644 index 000000000..6685250cd --- /dev/null +++ b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/tea-virtual-server_edge.yaml @@ -0,0 +1,16 @@ +apiVersion: cis.f5.com/v1 +kind: VirtualServer +metadata: + labels: + f5cr: "true" + name: tea-virtual-server-edge + namespace: default +spec: + host: tea.example.com + httpTraffic: redirect + pools: + - path: /neam + service: svc-edge + servicePort: 80 + tlsProfileName: edge-tls + virtualServerAddress: 172.16.3.4 \ No newline at end of file diff --git a/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/tea-virtual-server_reen.yaml b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/tea-virtual-server_reen.yaml new file mode 100644 index 000000000..dabd7feea --- /dev/null +++ b/docs/_static/config_examples/crd/tls/singledomain-with-edge-reencrypt-combination/tea-virtual-server_reen.yaml @@ -0,0 +1,19 @@ +apiVersion: cis.f5.com/v1 +kind: VirtualServer +metadata: + labels: + f5cr: "true" + name: tea-virtual-server-reen + namespace: default +spec: + host: tea.example.com + httpTraffic: redirect + pools: + - path: /green + service: svc-1 + servicePort: 80 + - path: /black + service: svc-2 + servicePort: 80 + tlsProfileName: reencrypt-tls + virtualServerAddress: 172.16.3.4 \ No newline at end of file diff --git a/docs/_static/config_examples/crd/tls/tls-with-health-monitor/README.md b/docs/_static/config_examples/crd/tls/tls-with-health-monitor/README.md new file mode 100644 index 000000000..e70b2e724 --- /dev/null +++ b/docs/_static/config_examples/crd/tls/tls-with-health-monitor/README.md @@ -0,0 +1,3 @@ +# Health Monitor + +This section demonstrates the deployment of Virtual Servers with Health Monitor. \ No newline at end of file diff --git a/docs/_static/config_examples/crd/tls/tls-with-httpredirect/README.md b/docs/_static/config_examples/crd/tls/tls-with-httpredirect/README.md new file mode 100644 index 000000000..701e3e6ad --- /dev/null +++ b/docs/_static/config_examples/crd/tls/tls-with-httpredirect/README.md @@ -0,0 +1,9 @@ +# Configure behaviour of HTTP Virtual Server + +This section demonstrates how to Configure behaviour HTTP Virtual Server. + +``` +// httpTraffic = allow -> Allows HTTP +// httpTraffic = none -> Only HTTPS +// httpTraffic = redirect -> redirects HTTP to HTTPS +``` \ No newline at end of file diff --git a/next-version.txt b/next-version.txt index 7ec1d6db4..7c3272873 100644 --- a/next-version.txt +++ b/next-version.txt @@ -1 +1 @@ -2.1.0 +2.1.1 \ No newline at end of file diff --git a/operator/build/Dockerfile b/operator/build/Dockerfile index 82d44bcae..8836f7773 100644 --- a/operator/build/Dockerfile +++ b/operator/build/Dockerfile @@ -3,7 +3,7 @@ FROM quay.io/operator-framework/helm-operator:latest ### Required OpenShift Labels LABEL name="F5 BIG-IP Controller Operator" \ vendor="F5 Networks Inc" \ - version="v1.1.0" \ + version="v1.2.0" \ release="1" \ summary="F5 BIG-IP Controller Operator" \ description="This operator will deploy F5 BIG-IP Controller for Kubernetes and OpenShift into the cluster." diff --git a/operator/deploy/crds/cis.f5.com_v1_f5bigipctlr_cr.yaml b/operator/deploy/crds/cis.f5.com_v1_f5bigipctlr_cr.yaml index 811d02196..78d229714 100644 --- a/operator/deploy/crds/cis.f5.com_v1_f5bigipctlr_cr.yaml +++ b/operator/deploy/crds/cis.f5.com_v1_f5bigipctlr_cr.yaml @@ -3,7 +3,7 @@ kind: F5BigIpCtlr metadata: name: f5-server spec: - version: 2.0.0 + version: 2.1.0 args: log_as3_response: true manage_routes: true diff --git a/operator/helm-charts/f5-bigip-ctlr/Chart.yaml b/operator/helm-charts/f5-bigip-ctlr/Chart.yaml index a0c755582..6ae41bff7 100644 --- a/operator/helm-charts/f5-bigip-ctlr/Chart.yaml +++ b/operator/helm-charts/f5-bigip-ctlr/Chart.yaml @@ -1,5 +1,4 @@ apiVersion: v1 -description: Deploy the F5 Networks BIG-IP Controller for Kubernetes and OpenShift - (k8s-bigip-ctlr). +description: Deploy the F5 Networks BIG-IP Controller for Kubernetes and OpenShift (k8s-bigip-ctlr). name: f5-bigip-ctlr -version: 0.0.7 +version: 0.0.8 diff --git a/operator/helm-charts/f5-bigip-ctlr/templates/_helpers.tpl b/operator/helm-charts/f5-bigip-ctlr/templates/_helpers.tpl index ff3a4b2b2..7ce05d2ef 100644 --- a/operator/helm-charts/f5-bigip-ctlr/templates/_helpers.tpl +++ b/operator/helm-charts/f5-bigip-ctlr/templates/_helpers.tpl @@ -6,6 +6,28 @@ Expand the name of the chart. {{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} {{- end -}} +{{/* +Return the appropriate apiVersion for deployment. +*/}} +{{- define "deployment.apiVersion" -}} +{{- if semverCompare ">=1.9-0" .Capabilities.KubeVersion.GitVersion -}} +{{- print "apps/v1" -}} +{{- else -}} +{{- print "extensions/v1beta1" -}} +{{- end -}} +{{- end -}} + +{{/* +Check for user given namespace or give kube-system +*/}} +{{- define "f5-bigip-ctlr.namespace" -}} +{{- if hasKey .Values "namespace" -}} +{{- .Values.namespace -}} +{{- else -}} +{{- print "kube-system" -}} +{{- end -}} +{{- end -}} + {{/* Create a default fully qualified app name. We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). @@ -23,7 +45,6 @@ If release name contains chart name it will be used as a full name. {{- end -}} {{- end -}} {{- end -}} - {{/* Create chart name and version as used by the chart label. */}} @@ -31,18 +52,7 @@ Create chart name and version as used by the chart label. {{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}} {{- end -}} -{{/* -Return the appropriate apiVersion for deployment. -*/}} -{{- define "deployment.apiVersion" -}} -{{- if semverCompare ">=1.9-0" .Capabilities.KubeVersion.GitVersion -}} -{{- print "apps/v1" -}} -{{- else -}} -{{- print "extensions/v1beta1" -}} -{{- end -}} -{{- end -}} - -{{/* + {{/* Create the name of the service account to use */}} {{- define "f5-bigip-ctlr.serviceAccountName" -}} @@ -52,14 +62,3 @@ Create the name of the service account to use {{ default "default" .Values.serviceAccount.name }} {{- end -}} {{- end -}} - -{{/* -Check for user given namespace or give kube-system -*/}} -{{- define "f5-bigip-ctlr.namespace" -}} -{{- if hasKey .Values "namespace" -}} -{{- .Values.namespace -}} -{{- else -}} -{{- print "kube-system" -}} -{{- end -}} -{{- end -}} diff --git a/operator/helm-charts/f5-bigip-ctlr/templates/f5-bigip-ctlr-clusterrole.yaml b/operator/helm-charts/f5-bigip-ctlr/templates/f5-bigip-ctlr-clusterrole.yaml index 0b30d0738..bd44d3249 100644 --- a/operator/helm-charts/f5-bigip-ctlr/templates/f5-bigip-ctlr-clusterrole.yaml +++ b/operator/helm-charts/f5-bigip-ctlr/templates/f5-bigip-ctlr-clusterrole.yaml @@ -44,4 +44,14 @@ rules: - events - ingresses/status - routes/status + - verbs: + - get + - list + - watch + - update + apiGroups: + - cis.f5.com + resources: + - virtualservers + - tlsprofiles {{- end -}} diff --git a/operator/helm-charts/f5-bigip-ctlr/templates/f5-bigip-ctlr-customresourcedefinitions.yml b/operator/helm-charts/f5-bigip-ctlr/templates/f5-bigip-ctlr-customresourcedefinitions.yml new file mode 100644 index 000000000..3b67d1d3c --- /dev/null +++ b/operator/helm-charts/f5-bigip-ctlr/templates/f5-bigip-ctlr-customresourcedefinitions.yml @@ -0,0 +1,115 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + name: virtualservers.cis.f5.com +spec: + group: cis.f5.com + names: + kind: VirtualServer + plural: virtualservers + shortNames: + - vs + singular: virtualserver + scope: Namespaced + versions: + - + name: v1 + served: true + storage: true + schema: + openAPIV3Schema: + type: object + properties: + spec: + type: object + properties: + host: + type: string + pattern: '^(([a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9\-]*[a-zA-Z0-9])\.)*([A-Za-z0-9]|[A-Za-z0-9][A-Za-z0-9\-]*[A-Za-z0-9])$' + httpTraffic: + type: string + tlsProfileName: + type: string + pools: + type: array + items: + type: object + properties: + path: + type: string + pattern: '^\/([A-z0-9-_+]+\/)*([A-z0-9]+\/?)*$' + service: + type: string + pattern: '^([A-z0-9-_+])*([A-z0-9])$' + nodeMemberLabel: + type: string + pattern: '^[a-zA-Z0-9][-A-Za-z0-9_.]{0,61}[a-zA-Z0-9]=[a-zA-Z0-9][-A-Za-z0-9_.]{0,61}[a-zA-Z0-9]$' + servicePort: + type: integer + minimum: 1 + maximum: 65535 + monitor: + type: object + properties: + type: + type: string + enum: [http, https] + send: + type: string + recv: + type: string + interval: + type: integer + timeout: + type: integer + virtualServerAddress: + type: string + pattern: '^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])$' + required: + - virtualServerAddress + +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + name: tlsprofiles.cis.f5.com +spec: + group: cis.f5.com + names: + kind: TLSProfile + plural: tlsprofiles + shortNames: + - tls + singular: tlsprofile + scope: Namespaced + versions: + - + name: v1 + served: true + storage: true + schema: + openAPIV3Schema: + type: object + properties: + spec: + type: object + properties: + hosts: + type: array + items: + type: string + pattern: '^(([a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9\-]*[a-zA-Z0-9])\.)*([A-Za-z0-9]|[A-Za-z0-9][A-Za-z0-9\-]*[A-Za-z0-9])$' + tls: + type: object + properties: + termination: + type: string + enum: [edge, reencrypt, passthrough] + clientSSL: + type: string + serverSSL: + type: string + reference: + type: string + required: + - clientSSL \ No newline at end of file diff --git a/operator/manifest/f5-bundle.zip b/operator/manifest/f5-bundle.zip new file mode 100644 index 000000000..575aeafde Binary files /dev/null and b/operator/manifest/f5-bundle.zip differ diff --git a/operator/manifest/f5-bigip-ctlr-operator.v1.1.0.clusterserviceversion.yaml b/operator/manifest/f5-bundle/1.1.0/f5-bigip-ctlr-operator.v1.1.0.clusterserviceversion.yaml similarity index 99% rename from operator/manifest/f5-bigip-ctlr-operator.v1.1.0.clusterserviceversion.yaml rename to operator/manifest/f5-bundle/1.1.0/f5-bigip-ctlr-operator.v1.1.0.clusterserviceversion.yaml index e8b6d5387..674358ea6 100644 --- a/operator/manifest/f5-bigip-ctlr-operator.v1.1.0.clusterserviceversion.yaml +++ b/operator/manifest/f5-bundle/1.1.0/f5-bigip-ctlr-operator.v1.1.0.clusterserviceversion.yaml @@ -8,7 +8,7 @@ metadata: [{"apiVersion":"cis.f5.com/v1","kind":"F5BigIpCtlr","metadata":{"name":"f5-server"},"spec":{"args":{"log_as3_response":true,"manage_routes":true,"agent":"as3","log_level":"","route_vserver_addr":"","bigip_partition":"","openshift_sdn_name":"","bigip_url":"","insecure":true,"pool-member-type":""},"bigip_login_secret":"","image":{"pullPolicy":"Always","repo":"k8s-bigip-ctlr","user":"f5networks"},"namespace":"kube-system","rbac":{"create":true},"resources":{},"serviceAccount":{"create":true,"name":null},"version":"latest"}}] categories: Networking certified: 'false' - createdAt: '2020-02-07' + createdAt: '2020-07-30' description: >- Operator to install F5 Container Ingress Services (CIS) for BIG-IP. containerImage: 'registry.connect.redhat.com/f5networks/k8s-bigip-ctlr-operator:latest' @@ -53,7 +53,7 @@ spec: maturity: beta version: 1.1.0 replaces: '' - minKubeVersion: 2.0.0 + minKubeVersion: 1.13.0 keywords: - Ingress Controller - BIGIP diff --git a/operator/manifest/f5bigipctlrs.cis.f5.com.crd.yaml b/operator/manifest/f5-bundle/1.1.0/f5bigipctlrs.cis.f5.com.crd.yaml similarity index 100% rename from operator/manifest/f5bigipctlrs.cis.f5.com.crd.yaml rename to operator/manifest/f5-bundle/1.1.0/f5bigipctlrs.cis.f5.com.crd.yaml diff --git a/operator/manifest/f5-bundle/1.2.0/f5-bigip-ctlr-operator.v1.2.0.clusterserviceversion.yaml b/operator/manifest/f5-bundle/1.2.0/f5-bigip-ctlr-operator.v1.2.0.clusterserviceversion.yaml new file mode 100644 index 000000000..4e6bb0681 --- /dev/null +++ b/operator/manifest/f5-bundle/1.2.0/f5-bigip-ctlr-operator.v1.2.0.clusterserviceversion.yaml @@ -0,0 +1,252 @@ +apiVersion: operators.coreos.com/v1alpha1 +kind: ClusterServiceVersion +metadata: + name: f5-bigip-ctlr-operator.v1.2.0 + namespace: placeholder + annotations: + alm-examples: >- + [{"apiVersion":"cis.f5.com/v1","kind":"F5BigIpCtlr","metadata":{"name":"f5-server"},"spec":{"args":{"log_as3_response":true,"manage_routes":true,"agent":"as3","log_level":"","route_vserver_addr":"","bigip_partition":"","openshift_sdn_name":"","bigip_url":"","insecure":true,"pool-member-type":""},"bigip_login_secret":"","image":{"pullPolicy":"Always","repo":"k8s-bigip-ctlr","user":"f5networks"},"namespace":"kube-system","rbac":{"create":true},"resources":{},"serviceAccount":{"create":true,"name":null},"version":"latest"}}] + categories: Networking + certified: 'false' + createdAt: '2020-08-21' + description: >- + Operator to install F5 Container Ingress Services (CIS) for BIG-IP. + containerImage: 'registry.connect.redhat.com/f5networks/k8s-bigip-ctlr-operator:latest' + support: F5 Operators Team + capabilities: Basic Install + repository: 'https://github.com/F5Networks/k8s-bigip-ctlr' +spec: + displayName: 'F5 Container Ingress Services' + description: > + ## Introduction + + This Operator installs F5 Container Ingress Services (CIS) for BIG-IP in + your Cluster. This enables to configure and deploy CIS using Helm Charts. + + ## F5 Container Ingress Services for BIG-IP + + F5 Container Ingress Services (CIS) integrates with container orchestration + environments to dynamically create L4/L7 services on F5 BIG-IP systems, and + load balance network traffic across the services. + + Monitoring the orchestration API server, CIS is able to modify the BIG-IP + system configuration based on changes made to containerized applications. + + ## Documentation + + Refer to F5 documentation + + - CIS on OpenShift (https://clouddocs.f5.com/containers/latest/userguide/openshift/) + - OpenShift Routes (https://clouddocs.f5.com/containers/latest/userguide/routes.html) + + ## Prerequisites + + Create BIG-IP login credentials for use with Operator Helm charts. A basic + way be, + + ``` + + oc create secret generic -n kube-system + --from-literal=username= --from-literal=password= + + ``` + maturity: beta + version: 1.2.0 + replaces: '' + minKubeVersion: 1.13.0 + keywords: + - Ingress Controller + - BIGIP + - F5 + - container + - router + - application + - delivery + - controller + - waf + - firewall + - loadbalancer + maintainers: + - name: F5 Operators Team + email: f5_cis_operators@f5.com + provider: + name: F5 Networks Inc. + labels: {} + selector: + matchLabels: {} + links: + - name: Documentation + url: 'https://clouddocs.f5.com/containers/latest/' + - name: Github Repo + url: 'https://github.com/F5Networks/k8s-bigip-ctlr/operator' + icon: + - base64data: >- +  + mediatype: image/png + customresourcedefinitions: + owned: + - name: f5bigipctlrs.cis.f5.com + displayName: F5BigIpCtlr + kind: F5BigIpCtlr + version: v1 + description: >- + This CRD provides kind `F5BigIpCtlr` to configure and deploy F5 BIG-IP + Controller. + resources: + - version: v1 + kind: Deployment + - version: v1 + kind: Service + - version: v1 + kind: ReplicaSet + - version: v1 + kind: Pod + - version: v1 + kind: Secret + - version: v1 + kind: ConfigMap + specDescriptors: + - description: Version is a read-only field. It contains the current version of F5 BIG-IP Controller Operator. + displayName: Version + path: version + statusDescriptors: + - path: phase + displayName: Status + description: Status of the F5 Container Ingress Services Operator. + x-descriptors: + - 'urn:alm:descriptor:io.kubernetes.phase' + required: [] + install: + strategy: deployment + spec: + clusterPermissions: + - serviceAccountName: f5-bigip-ctlr-operator + rules: + - apiGroups: + - '' + resources: + - pods + - services + - services/finalizers + - endpoints + - persistentvolumeclaims + - events + - configmaps + - secrets + - serviceaccounts + verbs: + - '*' + - apiGroups: + - apps + resources: + - deployments + - daemonsets + - replicasets + - statefulsets + verbs: + - '*' + - apiGroups: + - '' + resources: + - namespaces + verbs: + - '*' + - apiGroups: + - '' + resources: + - configmaps + - secrets + verbs: + - '*' + - apiGroups: + - monitoring.coreos.com + resources: + - servicemonitors + verbs: + - get + - create + - apiGroups: + - apps + resourceNames: + - f5-bigip-ctlr-operator + resources: + - deployments/finalizers + verbs: + - update + - apiGroups: + - '' + resources: + - pods + verbs: + - get + - apiGroups: + - apps + resources: + - replicasets + - deployments + verbs: + - get + - apiGroups: + - cis.f5.com + resources: + - '*' + verbs: + - '*' + - apiGroups: + - rbac.authorization.k8s.io + resources: + - clusterroles + - clusterrolebindings + - roles + - rolebindings + verbs: + - '*' + - apiGroups: + - apiextensions.k8s.io + resources: + - customresourcedefinitions + verbs: + - '*' + - apiGroups: + - charts.helm.k8s.io + resources: + - '*' + verbs: + - '*' + deployments: + - name: f5-bigip-ctlr-operator + spec: + replicas: 1 + selector: + matchLabels: + name: f5-bigip-ctlr-operator + template: + metadata: + labels: + name: f5-bigip-ctlr-operator + spec: + serviceAccountName: f5-bigip-ctlr-operator + containers: + - name: f5-bigip-ctlr-operator + image: registry.connect.redhat.com/f5networks/k8s-bigip-ctlr-operator:latest + imagePullPolicy: Always + env: + - name: WATCH_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.annotations['olm.targetNamespaces'] + - name: POD_NAME + valueFrom: + fieldRef: + fieldPath: metadata.name + - name: OPERATOR_NAME + value: f5-bigip-ctlr-operator + installModes: + - type: OwnNamespace + supported: true + - type: SingleNamespace + supported: true + - type: MultiNamespace + supported: true + - type: AllNamespaces + supported: true diff --git a/operator/manifest/f5-bundle/1.2.0/f5bigipctlrs.cis.f5.com.crd.yaml b/operator/manifest/f5-bundle/1.2.0/f5bigipctlrs.cis.f5.com.crd.yaml new file mode 100644 index 000000000..9e6743024 --- /dev/null +++ b/operator/manifest/f5-bundle/1.2.0/f5bigipctlrs.cis.f5.com.crd.yaml @@ -0,0 +1,19 @@ +apiVersion: apiextensions.k8s.io/v1beta1 +kind: CustomResourceDefinition +metadata: + name: f5bigipctlrs.cis.f5.com +spec: + group: cis.f5.com + names: + kind: F5BigIpCtlr + listKind: F5BigIpCtlrList + plural: f5bigipctlrs + singular: f5bigipctlr + scope: Namespaced + subresources: + status: {} + version: v1 + versions: + - name: v1 + served: true + storage: true diff --git a/operator/manifest/f5-bigip-ctlr-operator.package.yaml b/operator/manifest/f5-bundle/f5-bigip-ctlr-operator.package.yaml similarity index 57% rename from operator/manifest/f5-bigip-ctlr-operator.package.yaml rename to operator/manifest/f5-bundle/f5-bigip-ctlr-operator.package.yaml index b32cbb26e..3c60ee753 100644 --- a/operator/manifest/f5-bigip-ctlr-operator.package.yaml +++ b/operator/manifest/f5-bundle/f5-bigip-ctlr-operator.package.yaml @@ -1,4 +1,4 @@ packageName: f5-bigip-ctlr-operator channels: - name: beta - currentCSV: f5-bigip-ctlr-operator.v1.1.0 + currentCSV: f5-bigip-ctlr-operator.v1.2.0 diff --git a/operator/manifest/operator-latest.zip b/operator/manifest/operator-latest.zip deleted file mode 100644 index 80066015f..000000000 Binary files a/operator/manifest/operator-latest.zip and /dev/null differ diff --git a/pkg/agent/as3/as3Common.go b/pkg/agent/as3/as3Common.go index 74b20fdad..9f972df0f 100644 --- a/pkg/agent/as3/as3Common.go +++ b/pkg/agent/as3/as3Common.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/agent/as3/as3ConfigMap.go b/pkg/agent/as3/as3ConfigMap.go index 98f92bc15..6f8623037 100644 --- a/pkg/agent/as3/as3ConfigMap.go +++ b/pkg/agent/as3/as3ConfigMap.go @@ -53,6 +53,8 @@ func (am *AS3Manager) prepareResourceAS3ConfigMaps() ( if am.as3Validation == true { if ok := am.validateAS3Template(rscCfgMap.Data); !ok { log.Errorf("[AS3] Error validating AS3 template") + log.Errorf("[AS3] Error in processing the ConfigMap: %v/%v", + rscCfgMap.Namespace, rscCfgMap.Name) continue } } @@ -124,6 +126,8 @@ func (am *AS3Manager) processCfgMap(rscCfgMap *AgentCfgMap) ( obj, ok := getAS3ObjectFromTemplate(as3Tmpl) if !ok { log.Errorf("[AS3] Error processing AS3 template") + log.Errorf("[AS3] Error in processing the ConfigMap: %v/%v", + rscCfgMap.Namespace, rscCfgMap.Name) return nil, nil } diff --git a/pkg/agent/as3/as3Manager.go b/pkg/agent/as3/as3Manager.go index 1840e45e9..8957b9157 100644 --- a/pkg/agent/as3/as3Manager.go +++ b/pkg/agent/as3/as3Manager.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -30,10 +30,14 @@ import ( ) const ( - svcTenantLabel = "cis.f5.com/as3-tenant=" - svcAppLabel = "cis.f5.com/as3-app=" - svcPoolLabel = "cis.f5.com/as3-pool=" - as3SupportedVersion = 3.18 + svcTenantLabel = "cis.f5.com/as3-tenant=" + svcAppLabel = "cis.f5.com/as3-app=" + svcPoolLabel = "cis.f5.com/as3-pool=" + as3SupportedVersion = 3.18 + //Update as3Version,defaultAS3Version,defaultAS3Build while updating AS3 validation schema + as3Version = 3.21 + defaultAS3Version = "3.21.0" + defaultAS3Build = "4" as3tenant = "Tenant" as3class = "class" as3SharedApplication = "Shared" @@ -41,7 +45,7 @@ const ( as3shared = "shared" as3template = "template" //as3SchemaLatestURL = "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/latest/as3-schema.json" - as3SchemaFileName = "as3-schema-3.20.0-3-cis.json" + as3SchemaFileName = "as3-schema-3.21.0-4-cis.json" ) var baseAS3Config = `{ @@ -406,17 +410,25 @@ func (am *AS3Manager) IsBigIPAppServicesAvailable() error { return err } versionstr := version[:strings.LastIndex(version, ".")] - bigIPVersion, err := strconv.ParseFloat(versionstr, 64) + bigIPAS3Version, err := strconv.ParseFloat(versionstr, 64) if err != nil { log.Errorf("[AS3] Error while converting AS3 version to float") return err } - if bigIPVersion >= as3SupportedVersion { + if bigIPAS3Version >= as3SupportedVersion && bigIPAS3Version <= as3Version { log.Debugf("[AS3] BIGIP is serving with AS3 version: %v", version) return nil } + if bigIPAS3Version > as3Version { + am.as3Version = defaultAS3Version + as3Build := defaultAS3Build + am.as3Release = am.as3Version + "-" + as3Build + log.Debugf("[AS3] BIGIP is serving with AS3 version: %v", bigIPAS3Version) + return nil + } + return fmt.Errorf("CIS versions >= 2.0 are compatible with AS3 versions >= %v. "+ "Upgrade AS3 version in BIGIP from %v to %v or above.", as3SupportedVersion, - bigIPVersion, as3SupportedVersion) + bigIPAS3Version, as3SupportedVersion) } diff --git a/pkg/agent/as3/as3Manager_test.go b/pkg/agent/as3/as3Manager_test.go index 1d17cecc9..55e4bf4c0 100644 --- a/pkg/agent/as3/as3Manager_test.go +++ b/pkg/agent/as3/as3Manager_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -17,6 +17,7 @@ package as3 import ( "encoding/json" + . "github.com/F5Networks/k8s-bigip-ctlr/pkg/resource" . "github.com/onsi/ginkgo" . "github.com/onsi/gomega" @@ -45,8 +46,8 @@ var _ = Describe("AS3Manager Tests", func() { var mockMgr *mockAS3Manager BeforeEach(func() { mockMgr = newMockAS3Manager(&Params{ - As3Version: "3.20.0", - As3Release: "3.20.0-3", + As3Version: "3.21.0", + As3Release: "3.21.0-4", }) }) AfterEach(func() { diff --git a/pkg/agent/as3/as3Resource.go b/pkg/agent/as3/as3Resource.go index 2a85dc439..d6a719541 100644 --- a/pkg/agent/as3/as3Resource.go +++ b/pkg/agent/as3/as3Resource.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/agent/as3/as3Types.go b/pkg/agent/as3/as3Types.go index f0c36b396..8a2824318 100644 --- a/pkg/agent/as3/as3Types.go +++ b/pkg/agent/as3/as3Types.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/agent/as3/as3Utils.go b/pkg/agent/as3/as3Utils.go index abb0f1595..9fc166699 100644 --- a/pkg/agent/as3/as3Utils.go +++ b/pkg/agent/as3/as3Utils.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/agent/as3/as3Utils_test.go b/pkg/agent/as3/as3Utils_test.go index 9c52d1349..7a9e9afc0 100644 --- a/pkg/agent/as3/as3Utils_test.go +++ b/pkg/agent/as3/as3Utils_test.go @@ -2,6 +2,7 @@ package as3 import ( "io/ioutil" + "sort" . "github.com/onsi/ginkgo" . "github.com/onsi/gomega" @@ -62,6 +63,7 @@ var _ = Describe("Tenant parsing in AS3 declaration", func() { It("Get Tenants from a declaration", func() { cmcfg1 := readConfigFile(configPath + "as3config_multi_cm_unified.json") tenants := getTenants(as3Declaration(cmcfg1), true) + sort.Strings(tenants) Expect(tenants).To(Equal([]string{"Tenant1", "Tenant2"}), "Failed to get tenants") }) }) diff --git a/pkg/agent/as3/l2l3agent.go b/pkg/agent/as3/l2l3agent.go index 95ee3e303..6b880181c 100644 --- a/pkg/agent/as3/l2l3agent.go +++ b/pkg/agent/as3/l2l3agent.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/agent/as3/postManager.go b/pkg/agent/as3/postManager.go index ae3cf793d..131f347d4 100644 --- a/pkg/agent/as3/postManager.go +++ b/pkg/agent/as3/postManager.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/agent/cccl/ccclManager.go b/pkg/agent/cccl/ccclManager.go index b6cdc52a6..6138d2c4a 100644 --- a/pkg/agent/cccl/ccclManager.go +++ b/pkg/agent/cccl/ccclManager.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/agent/cccl/outputConfig.go b/pkg/agent/cccl/outputConfig.go index 79ae9afe7..2f74ab04a 100644 --- a/pkg/agent/cccl/outputConfig.go +++ b/pkg/agent/cccl/outputConfig.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/agentResponseHandler.go b/pkg/appmanager/agentResponseHandler.go index 73d6e2d1e..c52228dbe 100644 --- a/pkg/appmanager/agentResponseHandler.go +++ b/pkg/appmanager/agentResponseHandler.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/appManager.go b/pkg/appmanager/appManager.go index 43c7716b2..d2a78705a 100644 --- a/pkg/appmanager/appManager.go +++ b/pkg/appmanager/appManager.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -2434,6 +2434,23 @@ func containsNode(nodes []Node, name string) bool { return false } +type byTimestamp []v1.Service + +//sort services by timestamp +func (slice byTimestamp) Len() int { + return len(slice) +} + +func (slice byTimestamp) Less(i, j int) bool { + d1 := slice[i].GetCreationTimestamp() + d2 := slice[j].GetCreationTimestamp() + return d1.Before(&d2) +} + +func (slice byTimestamp) Swap(i, j int) { + slice[i], slice[j] = slice[j], slice[i] +} + // Performs Service discovery for the given AS3 Pool and returns a pool. // Service discovery is loosely coupled with Kubernetes Service labels. A Kubernetes Service is treated as a match for // an AS3 Pool, if the Kubernetes Service have the following labels and their values matches corresponding AS3 @@ -2461,14 +2478,16 @@ func (m *Manager) getEndpoints(selector, namespace string) []Member { } if len(services.Items) > 1 { - svcNames := "" + svcName := "" + sort.Sort(byTimestamp(services.Items)) + //picking up the oldest service + services.Items = services.Items[:1] for _, service := range services.Items { - svcNames += fmt.Sprintf("Service: %v, Namespace: %v \n", service.Name, service.Namespace) + svcName += fmt.Sprintf("Service: %v, Namespace: %v,Timestamp: %v\n", service.Name, service.Namespace, service.GetCreationTimestamp()) } - log.Errorf("[CORE] Multiple Services are tagged for this pool. Ignoring all endpoints.\n%v", svcNames) - return members + log.Warningf("[CORE] Multiple Services are tagged for this pool. Using oldest service endpoints.\n%v", svcName) } for _, service := range services.Items { diff --git a/pkg/appmanager/appManager_test.go b/pkg/appmanager/appManager_test.go index 96cbabc34..08e76c13d 100644 --- a/pkg/appmanager/appManager_test.go +++ b/pkg/appmanager/appManager_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/eventNotifier.go b/pkg/appmanager/eventNotifier.go index 8a9353761..781f5e3c5 100644 --- a/pkg/appmanager/eventNotifier.go +++ b/pkg/appmanager/eventNotifier.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -19,7 +19,7 @@ package appmanager import ( "sync" - "k8s.io/api/core/v1" + v1 "k8s.io/api/core/v1" "k8s.io/api/extensions/v1beta1" "k8s.io/apimachinery/pkg/runtime" "k8s.io/client-go/kubernetes/scheme" diff --git a/pkg/appmanager/eventNotifier_test.go b/pkg/appmanager/eventNotifier_test.go index af10ccd3d..30c2b02d6 100644 --- a/pkg/appmanager/eventNotifier_test.go +++ b/pkg/appmanager/eventNotifier_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -18,6 +18,7 @@ package appmanager import ( "fmt" + "github.com/F5Networks/k8s-bigip-ctlr/pkg/agent/cccl" "github.com/F5Networks/k8s-bigip-ctlr/pkg/agent" @@ -27,7 +28,7 @@ import ( . "github.com/onsi/gomega" fakeRouteClient "github.com/openshift/client-go/route/clientset/versioned/fake" - "k8s.io/api/core/v1" + v1 "k8s.io/api/core/v1" "k8s.io/api/extensions/v1beta1" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/apimachinery/pkg/runtime" diff --git a/pkg/appmanager/healthMonitors.go b/pkg/appmanager/healthMonitors.go index 6b5a628ee..202a4e6b5 100644 --- a/pkg/appmanager/healthMonitors.go +++ b/pkg/appmanager/healthMonitors.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/healthMonitors_test.go b/pkg/appmanager/healthMonitors_test.go index ca3781daa..b431d0419 100644 --- a/pkg/appmanager/healthMonitors_test.go +++ b/pkg/appmanager/healthMonitors_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -27,7 +27,7 @@ import ( routeapi "github.com/openshift/api/route/v1" fakeRouteClient "github.com/openshift/client-go/route/clientset/versioned/fake" - "k8s.io/api/core/v1" + v1 "k8s.io/api/core/v1" "k8s.io/api/extensions/v1beta1" "k8s.io/apimachinery/pkg/util/intstr" "k8s.io/client-go/kubernetes/fake" diff --git a/pkg/appmanager/profiles_test.go b/pkg/appmanager/profiles_test.go index 4ca586b96..d73c588fb 100644 --- a/pkg/appmanager/profiles_test.go +++ b/pkg/appmanager/profiles_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -18,9 +18,10 @@ package appmanager import ( "fmt" - "github.com/F5Networks/k8s-bigip-ctlr/pkg/agent/cccl" "sort" + "github.com/F5Networks/k8s-bigip-ctlr/pkg/agent/cccl" + "github.com/F5Networks/k8s-bigip-ctlr/pkg/agent" . "github.com/F5Networks/k8s-bigip-ctlr/pkg/resource" "github.com/F5Networks/k8s-bigip-ctlr/pkg/test" @@ -29,7 +30,7 @@ import ( routeapi "github.com/openshift/api/route/v1" fakeRouteClient "github.com/openshift/client-go/route/clientset/versioned/fake" - "k8s.io/api/core/v1" + v1 "k8s.io/api/core/v1" "k8s.io/api/extensions/v1beta1" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/apimachinery/pkg/util/intstr" diff --git a/pkg/appmanager/resourceConfig.go b/pkg/appmanager/resourceConfig.go index f5f3edb34..98c886641 100644 --- a/pkg/appmanager/resourceConfig.go +++ b/pkg/appmanager/resourceConfig.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/resourceConfig_test.go b/pkg/appmanager/resourceConfig_test.go index 9d0502996..15dc92cb3 100644 --- a/pkg/appmanager/resourceConfig_test.go +++ b/pkg/appmanager/resourceConfig_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/routing.go b/pkg/appmanager/routing.go index d8e0b3ff7..9627ec67f 100644 --- a/pkg/appmanager/routing.go +++ b/pkg/appmanager/routing.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/schema.go b/pkg/appmanager/schema.go index 85a0f32aa..f9232478c 100644 --- a/pkg/appmanager/schema.go +++ b/pkg/appmanager/schema.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/schema_test.go b/pkg/appmanager/schema_test.go index cd3111f7b..41cf16d20 100644 --- a/pkg/appmanager/schema_test.go +++ b/pkg/appmanager/schema_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/appmanager/validateResources.go b/pkg/appmanager/validateResources.go index dcccd6851..ec091afc5 100644 --- a/pkg/appmanager/validateResources.go +++ b/pkg/appmanager/validateResources.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/crmanager/backend.go b/pkg/crmanager/backend.go index 0c75339a3..66c66e6f4 100644 --- a/pkg/crmanager/backend.go +++ b/pkg/crmanager/backend.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -202,8 +202,9 @@ func processDataGroupForAS3(intDgMap InternalDataGroupMap, sharedApp as3Applicat for _, record := range dg.Records { var rec as3Record rec.Key = record.Name + virtualAddress := extractVirtualAddress(record.Data) // To override default Value created for CCCL for certain DG types - if val, ok := getDGRecordValueForAS3(idk.Name, sharedApp); ok { + if val, ok := getDGRecordValueForAS3(idk.Name, sharedApp, virtualAddress); ok { rec.Value = val } else { rec.Value = record.Data @@ -217,8 +218,9 @@ func processDataGroupForAS3(intDgMap InternalDataGroupMap, sharedApp as3Applicat for _, record := range dg.Records { var rec as3Record rec.Key = record.Name + virtualAddress := extractVirtualAddress(record.Data) // To override default Value created for CCCL for certain DG types - if val, ok := getDGRecordValueForAS3(idk.Name, sharedApp); ok { + if val, ok := getDGRecordValueForAS3(idk.Name, sharedApp, virtualAddress); ok { rec.Value = val } else { rec.Value = record.Data @@ -236,16 +238,25 @@ func processDataGroupForAS3(intDgMap InternalDataGroupMap, sharedApp as3Applicat } } -func getDGRecordValueForAS3(dgName string, sharedApp as3Application) (string, bool) { +func extractVirtualAddress(str string) string { + var address string + if strings.HasPrefix(str, "crd_") && strings.HasSuffix(str, "_tls_client") { + address = strings.ReplaceAll(strings.TrimRight(strings.TrimLeft(str, "crd_"), "_tls_client"), "_", ".") + } + return address +} + +func getDGRecordValueForAS3(dgName string, sharedApp as3Application, virtualAddress string) (string, bool) { switch dgName { case ReencryptServerSslDgName: for _, v := range sharedApp { - if svc, ok := v.(*as3Service); ok && svc.Class == "Service_HTTPS" { + if svc, ok := v.(*as3Service); ok && svc.Class == "Service_HTTPS" && + svc.VirtualAddresses[0] == virtualAddress { if val, ok := svc.ClientTLS.(*as3ResourcePointer); ok { return val.BigIP, true } if val, ok := svc.ClientTLS.(string); ok { - return strings.Join([]string{"", DEFAULT_PARTITION, as3SharedApplication, val}, "/"), true + return strings.Join([]string{"", val}, ""), true } log.Errorf("Unable to find serverssl for Data Group: %v\n", dgName) } @@ -609,9 +620,8 @@ func processCustomProfilesForAS3(customProfiles *CustomProfileStore, sharedApp a createCertificateDecl(prof, sharedApp) } else { createUpdateCABundle(prof, caBundleName, sharedApp) - if tlsClient == nil { - tlsClient = createTLSClient(prof, svcName, caBundleName, sharedApp) - } + tlsClient = createTLSClient(prof, svcName, caBundleName, sharedApp) + skey := SecretKey{ Name: prof.Name + "-ca", } @@ -692,7 +702,7 @@ func createTLSClient( sharedApp as3Application, ) *as3TLSClient { // For TLSClient only Cert (DestinationCACertificate) is given and key is empty string - if "" != prof.Cert && "" == prof.Key { + if _, ok := sharedApp[svcName]; "" != prof.Cert && "" == prof.Key && ok { svc := sharedApp[svcName].(*as3Service) tlsClientName := fmt.Sprintf("%s_tls_client", svcName) diff --git a/pkg/crmanager/crManager.go b/pkg/crmanager/crManager.go index d56358d6a..75e58de53 100644 --- a/pkg/crmanager/crManager.go +++ b/pkg/crmanager/crManager.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/crmanager/informers.go b/pkg/crmanager/informers.go index a140500a6..098ba9ac5 100644 --- a/pkg/crmanager/informers.go +++ b/pkg/crmanager/informers.go @@ -1,5 +1,5 @@ /*- -* Copyright (c) 2016-2019, F5 Networks, Inc. +* Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -143,7 +143,7 @@ func (crMgr *CRManager) addEventHandlers(crInf *CRInformer) { crInf.vsInformer.AddEventHandler( &cache.ResourceEventHandlerFuncs{ AddFunc: func(obj interface{}) { crMgr.enqueueVirtualServer(obj) }, - UpdateFunc: func(old, cur interface{}) { crMgr.enqueueVirtualServer(cur) }, + UpdateFunc: func(old, cur interface{}) { crMgr.enqueueUpdatedVirtualServer(old, cur) }, DeleteFunc: func(obj interface{}) { crMgr.enqueueDeletedVirtualServer(obj) }, }, ) @@ -202,6 +202,33 @@ func (crMgr *CRManager) enqueueVirtualServer(obj interface{}) { crMgr.rscQueue.Add(key) } +func (crMgr *CRManager) enqueueUpdatedVirtualServer(oldObj, newObj interface{}) { + oldVS := oldObj.(*cisapiv1.VirtualServer) + newVS := newObj.(*cisapiv1.VirtualServer) + + if oldVS.Spec.VirtualServerAddress != newVS.Spec.VirtualServerAddress { + log.Infof("Enqueueing VirtualServer: %v", oldVS) + key := &rqKey{ + namespace: oldVS.ObjectMeta.Namespace, + kind: VirtualServer, + rscName: oldVS.ObjectMeta.Name, + rsc: oldObj, + rscDelete: true, + } + crMgr.rscQueue.Add(key) + } + + log.Infof("Enqueueing VirtualServer: %v", newVS) + key := &rqKey{ + namespace: newVS.ObjectMeta.Namespace, + kind: VirtualServer, + rscName: newVS.ObjectMeta.Name, + rsc: newObj, + } + + crMgr.rscQueue.Add(key) +} + func (crMgr *CRManager) enqueueDeletedVirtualServer(obj interface{}) { vs := obj.(*cisapiv1.VirtualServer) log.Infof("Enqueueing VirtualServer: %v", vs) @@ -230,27 +257,46 @@ func (crMgr *CRManager) enqueueTLSServer(obj interface{}) { } func (crMgr *CRManager) enqueueService(obj interface{}) { + flag := true svc := obj.(*corev1.Service) - log.Infof("Enqueueing Service: %v", svc) - key := &rqKey{ - namespace: svc.ObjectMeta.Namespace, - kind: Service, - rscName: svc.ObjectMeta.Name, - rsc: obj, + log.Debugf("Enqueueing Service: %v", svc) + ignoresvcList := []string{"kube-dns", "kube-scheduler", "kube-controller-manager", "docker-registry", "kubernetes", "registry-console", "router", "kubelet", "console", "alertmanager-main", "alertmanager-operated", "cluster-monitoring-operator", "grafana", "kube-state-metrics", "node-exporter", "prometheus-k8s", "prometheus-operated", "prometheus-operatorwebconsole"} + for _, svcName := range ignoresvcList { + if svc.ObjectMeta.Name == svcName { + flag = false + break + } + } + if flag { + key := &rqKey{ + namespace: svc.ObjectMeta.Namespace, + kind: Service, + rscName: svc.ObjectMeta.Name, + rsc: obj, + } + crMgr.rscQueue.Add(key) } - - crMgr.rscQueue.Add(key) } func (crMgr *CRManager) enqueueEndpoints(obj interface{}) { + flag := true eps := obj.(*corev1.Endpoints) - log.Infof("Enqueueing Endpoints: %v", eps) - key := &rqKey{ - namespace: eps.ObjectMeta.Namespace, - kind: Endpoints, - rscName: eps.ObjectMeta.Name, - rsc: obj, + log.Debugf("Enqueueing Endpoints: %v", eps) + ignoreeplist := []string{"kube-dns", "kube-scheduler", "kube-controller-manager", "docker-registry", "kubernetes", "registry-console", "router", "kubelet", "console", "alertmanager-main", "alertmanager-operated", "cluster-monitoring-operator", "grafana", "kube-state-metrics", "node-exporter", "prometheus-k8s", "prometheus-operated", "prometheus-operatorwebconsole"} + for _, epname := range ignoreeplist { + if eps.ObjectMeta.Name == epname { + flag = false + break + } } + if flag { + key := &rqKey{ + namespace: eps.ObjectMeta.Namespace, + kind: Endpoints, + rscName: eps.ObjectMeta.Name, + rsc: obj, + } - crMgr.rscQueue.Add(key) + crMgr.rscQueue.Add(key) + } } diff --git a/pkg/crmanager/postManager.go b/pkg/crmanager/postManager.go index d25be02ba..f506b63de 100644 --- a/pkg/crmanager/postManager.go +++ b/pkg/crmanager/postManager.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/crmanager/profile.go b/pkg/crmanager/profile.go index 0511c3f47..422d50de1 100644 --- a/pkg/crmanager/profile.go +++ b/pkg/crmanager/profile.go @@ -2,23 +2,94 @@ package crmanager import ( "fmt" - v1 "k8s.io/api/core/v1" "reflect" + + v1 "k8s.io/api/core/v1" ) -// Creates a default SNI profile (if needed) and a new profile from a Secret -func (crMgr *CRManager) createSecretSslProfile( +// Creates a new ClientSSL profile from a Secret +func (crMgr *CRManager) createSecretClientSSLProfile( rsCfg *ResourceConfig, secret *v1.Secret, context string, ) (error, bool) { + + if _, ok := secret.Data["tls.key"]; !ok { + err := fmt.Errorf("Invalid Secret '%v': 'tls.key' field not specified.", + secret.ObjectMeta.Name) + return err, false + } + if _, ok := secret.Data["tls.crt"]; !ok { err := fmt.Errorf("Invalid Secret '%v': 'tls.crt' field not specified.", secret.ObjectMeta.Name) return err, false } - if _, ok := secret.Data["tls.key"]; !ok { - err := fmt.Errorf("Invalid Secret '%v': 'tls.key' field not specified.", + + // Create Default for SNI profile + skey := SecretKey{ + Name: fmt.Sprintf("default-%s-%s", context, rsCfg.GetName()), + ResourceName: rsCfg.GetName(), + } + sni := ProfileRef{ + Name: skey.Name, + Partition: rsCfg.Virtual.Partition, + Context: context, + } + if _, ok := crMgr.customProfiles.Profs[skey]; !ok { + // This is just a basic profile, so we don't need all the fields + cp := NewCustomProfile(sni, "", "", "", true, "", "") + crMgr.customProfiles.Profs[skey] = cp + } + // TODO + //rsCfg.Virtual.AddOrUpdateProfile(sni) + + // Now add the resource profile + profRef := ProfileRef{ + Name: secret.ObjectMeta.Name, + Partition: rsCfg.Virtual.Partition, + Context: context, + Namespace: secret.ObjectMeta.Namespace, + } + cp := NewCustomProfile( + profRef, + string(secret.Data["tls.crt"]), + string(secret.Data["tls.key"]), + "", // serverName + false, // sni + "", // peerCertMode + "", // caFile + ) + skey = SecretKey{ + Name: cp.Name, + ResourceName: rsCfg.GetName(), + } + crMgr.customProfiles.Lock() + defer crMgr.customProfiles.Unlock() + if prof, ok := crMgr.customProfiles.Profs[skey]; ok { + if !reflect.DeepEqual(prof, cp) { + crMgr.customProfiles.Profs[skey] = cp + rsCfg.Virtual.AddOrUpdateProfile(profRef) + return nil, true + } else { + return nil, false + } + } + crMgr.customProfiles.Profs[skey] = cp + rsCfg.Virtual.AddOrUpdateProfile(profRef) + return nil, false +} + +// Creates a new ServerSSL profile from a Secret +func (crMgr *CRManager) createSecretServerSSLProfile( + rsCfg *ResourceConfig, + secret *v1.Secret, + context string, +) (error, bool) { + + // tls.key is not mandatory for ServerSSL Profile + if _, ok := secret.Data["tls.crt"]; !ok { + err := fmt.Errorf("Invalid Secret '%v': 'tls.crt' field not specified.", secret.ObjectMeta.Name) return err, false } @@ -51,7 +122,7 @@ func (crMgr *CRManager) createSecretSslProfile( cp := NewCustomProfile( profRef, string(secret.Data["tls.crt"]), - string(secret.Data["tls.key"]), + "", "", // serverName false, // sni "", // peerCertMode diff --git a/pkg/crmanager/pythonDriver.go b/pkg/crmanager/pythonDriver.go index 5bb225a4d..1037929d4 100644 --- a/pkg/crmanager/pythonDriver.go +++ b/pkg/crmanager/pythonDriver.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2019, F5 Networks, Inc. + * Copyright (c) 2019-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/crmanager/resourceConfig.go b/pkg/crmanager/resourceConfig.go index 72ab61c46..d24f61a94 100644 --- a/pkg/crmanager/resourceConfig.go +++ b/pkg/crmanager/resourceConfig.go @@ -1,5 +1,5 @@ /*- -* Copyright (c) 2016-2019, F5 Networks, Inc. +* Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -318,6 +318,8 @@ func formatVirtualServerName(ip string, port int32) string { func formatVirtualServerPoolName(namespace, svc string, nodeMemberLabel string) string { poolName := fmt.Sprintf("%s_%s", namespace, svc) if nodeMemberLabel != "" { + replacer := strings.NewReplacer("=", "_") + nodeMemberLabel = replacer.Replace(nodeMemberLabel) poolName = fmt.Sprintf("%s_%s", poolName, nodeMemberLabel) } return AS3NameFormatter(poolName) @@ -341,7 +343,7 @@ func (crMgr *CRManager) prepareRSConfigFromVirtualServer( var pools Pools var rules *Rules var plcy *Policy - + var poolExist bool var monitors []Monitor for _, pl := range vs.Spec.Pools { pool := Pool{ @@ -355,6 +357,16 @@ func (crMgr *CRManager) prepareRSConfigFromVirtualServer( ServicePort: pl.ServicePort, NodeMemberLabel: pl.NodeMemberLabel, } + for _, p := range pools { + if pool.Name == p.Name { + poolExist = true + break + } + } + if poolExist { + poolExist = false + continue + } if pl.Monitor.Send != "" && pl.Monitor.Type != "" { pool.MonitorNames = append(pool.MonitorNames, JoinBigipPath(DEFAULT_PARTITION, @@ -459,7 +471,7 @@ func (crMgr *CRManager) handleVirtualServerTLS( if secret, ok := crMgr.SSLContext[clientSSL]; ok { log.Debugf("clientSSL secret %s for TLSProfile '%s' is already available with CIS in "+ "SSLContext as clientSSL", secret.ObjectMeta.Name, tlsName) - err, _ := crMgr.createSecretSslProfile(rsCfg, secret, CustomProfileClient) + err, _ := crMgr.createSecretClientSSLProfile(rsCfg, secret, CustomProfileClient) if err != nil { log.Debugf("error %v encountered for '%s' using TLSProfile '%s'", err, vsName, tlsName) @@ -468,8 +480,7 @@ func (crMgr *CRManager) handleVirtualServerTLS( } else { // Check if profile is contained in a Secret // Update the SSL Context if secret found, This is used to avoid api calls - log.Debugf("clientSSL secret for TLSProfile '%s' does not exist with CIS in "+ - "SSLContext", tlsName) + log.Debugf("saving clientSSL secret for TLSProfile '%s' into SSLContext", tlsName) secret, err := crMgr.kubeClient.CoreV1().Secrets(vsNamespace). Get(clientSSL, metav1.GetOptions{}) if err != nil { @@ -478,7 +489,7 @@ func (crMgr *CRManager) handleVirtualServerTLS( return false } crMgr.SSLContext[clientSSL] = secret - error, _ := crMgr.createSecretSslProfile(rsCfg, secret, CustomProfileClient) + error, _ := crMgr.createSecretClientSSLProfile(rsCfg, secret, CustomProfileClient) if error != nil { log.Errorf("error %v encountered for '%s' using TLSProfile '%s'", error, vsName, tlsName) @@ -492,7 +503,7 @@ func (crMgr *CRManager) handleVirtualServerTLS( if secret, ok := crMgr.SSLContext[serverSSL]; ok { log.Debugf("serverSSL secret %s for TLSProfile '%s' is already available with CIS in"+ "SSLContext", secret.ObjectMeta.Name, tlsName) - err, _ := crMgr.createSecretSslProfile(rsCfg, secret, CustomProfileServer) + err, _ := crMgr.createSecretServerSSLProfile(rsCfg, secret, CustomProfileServer) if err != nil { log.Debugf("error %v encountered for '%s' using TLSProfile '%s'", err, vsName, tlsName) @@ -501,8 +512,7 @@ func (crMgr *CRManager) handleVirtualServerTLS( } else { // Check if profile is contained in a Secret // Update the SSL Context if secret found, This is used to avoid api calls - log.Debugf("serverSSL secret for TLSProfile '%s' does not exist with CIS in "+ - "SSLContext", tlsName) + log.Debugf("saving serverSSL secret for TLSProfile '%s' into SSLContext", tlsName) secret, err := crMgr.kubeClient.CoreV1().Secrets(vsNamespace). Get(serverSSL, metav1.GetOptions{}) if err != nil { @@ -511,7 +521,7 @@ func (crMgr *CRManager) handleVirtualServerTLS( return false } crMgr.SSLContext[serverSSL] = secret - error, _ := crMgr.createSecretSslProfile(rsCfg, secret, CustomProfileServer) + error, _ := crMgr.createSecretServerSSLProfile(rsCfg, secret, CustomProfileServer) if error != nil { log.Errorf("error %v encountered for '%s' using TLSProfile '%s'", error, vsName, tlsName) @@ -526,8 +536,7 @@ func (crMgr *CRManager) handleVirtualServerTLS( } // TLS Cert/Key for _, pl := range vs.Spec.Pools { - if "" != vs.Spec.TLSProfileName && - pl.ServicePort == DEFAULT_HTTPS_PORT { + if "" != vs.Spec.TLSProfileName { switch tls.Spec.TLS.Termination { case TLSEdge: serverSsl := "false" @@ -543,7 +552,7 @@ func (crMgr *CRManager) handleVirtualServerTLS( path := pl.Path sslPath := hostName + path sslPath = strings.TrimSuffix(sslPath, "/") - serverSsl := AS3NameFormatter("f5_crd_" + vs.Spec.VirtualServerAddress + "_tls_client") + serverSsl := AS3NameFormatter("crd_" + vs.Spec.VirtualServerAddress + "_tls_client") if "" != tls.Spec.TLS.ServerSSL { updateDataGroup(crMgr.intDgMap, ReencryptServerSslDgName, DEFAULT_PARTITION, vs.ObjectMeta.Namespace, sslPath, serverSsl) @@ -561,6 +570,11 @@ func (crMgr *CRManager) handleVirtualServerTLS( PassthroughHostsDgName, ) case TLSReencrypt: + if vs.Spec.HTTPTraffic == TLSAllowInsecure { + log.Errorf("Error in processing Virtual '%s' using TLSProfile '%s' as httpTraffic is configured as ALLOW for reencrypt Termination", + vsName, tlsName) + return false + } updateDataGroupOfDgName( crMgr.intDgMap, vs, @@ -621,6 +635,40 @@ func (crMgr *CRManager) handleVirtualServerTLS( return true } +// validate TLSProfile +// validation includes valid parameters for the type of termination(edge, re-encrypt and Pass-through) +func validateTLSProfile(tls *cisapiv1.TLSProfile) bool { + //validation for re-encrypt termination + if tls.Spec.TLS.Termination == "reencrypt" { + // Should contain both client and server SSL profiles + if (tls.Spec.TLS.ClientSSL == "") || (tls.Spec.TLS.ServerSSL == "") { + log.Errorf("TLSProfile %s of type re-encrypt termination should contain both "+ + "ClientSSL and ServerSSL", tls.ObjectMeta.Name) + return false + } + } else if tls.Spec.TLS.Termination == "edge" { + // Should contain only client SSL + if tls.Spec.TLS.ClientSSL == "" { + log.Errorf("TLSProfile %s of type edge termination should contain Client SSL", + tls.ObjectMeta.Name) + return false + } + if tls.Spec.TLS.ServerSSL != "" { + log.Errorf("TLSProfile %s of type edge termination should NOT contain ServerSSL", + tls.ObjectMeta.Name) + return false + } + } else { + // Pass-through + if (tls.Spec.TLS.ClientSSL != "") || (tls.Spec.TLS.ServerSSL != "") { + log.Errorf("TLSProfile %s of type Pass-through termination should NOT contain either "+ + "ClientSSL or ServerSSL", tls.ObjectMeta.Name) + return false + } + } + return true +} + // ConvertStringToProfileRef converts strings to profile references func ConvertStringToProfileRef(profileName, context, ns string) ProfileRef { profName := strings.TrimSpace(strings.TrimPrefix(profileName, "/")) diff --git a/pkg/crmanager/routing.go b/pkg/crmanager/routing.go index fd98dbc9c..2b270f790 100644 --- a/pkg/crmanager/routing.go +++ b/pkg/crmanager/routing.go @@ -1,5 +1,5 @@ /*- -* Copyright (c) 2016-2019, F5 Networks, Inc. +* Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -757,13 +757,13 @@ func updateDataGroupOfDgName( path := pl.Path routePath := hostName + path routePath = strings.TrimSuffix(routePath, "/") - poolName := formatVirtualServerPoolName(namespace, pl.Service, "") + poolName := formatVirtualServerPoolName(namespace, pl.Service, pl.NodeMemberLabel) updateDataGroup(intDgMap, dgName, DEFAULT_PARTITION, namespace, routePath, poolName) } case PassthroughHostsDgName: for _, pl := range virtual.Spec.Pools { - poolName := formatVirtualServerPoolName(namespace, pl.Service, "") + poolName := formatVirtualServerPoolName(namespace, pl.Service, pl.NodeMemberLabel) updateDataGroup(intDgMap, dgName, DEFAULT_PARTITION, namespace, hostName, poolName) } diff --git a/pkg/crmanager/types.go b/pkg/crmanager/types.go index 2eaaa8de5..4302f6641 100644 --- a/pkg/crmanager/types.go +++ b/pkg/crmanager/types.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/crmanager/validate.go b/pkg/crmanager/validate.go index 7ee06c718..68b5eb60b 100644 --- a/pkg/crmanager/validate.go +++ b/pkg/crmanager/validate.go @@ -1,5 +1,5 @@ /*- -* Copyright (c) 2016-2019, F5 Networks, Inc. +* Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/crmanager/worker.go b/pkg/crmanager/worker.go index 0806db6c5..05b67e063 100644 --- a/pkg/crmanager/worker.go +++ b/pkg/crmanager/worker.go @@ -1,5 +1,5 @@ /*- -* Copyright (c) 2016-2019, F5 Networks, Inc. +* Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -186,7 +186,7 @@ func (crMgr *CRManager) syncService(svc *v1.Service) []*cisapiv1.VirtualServer { // find VirtualServers that reference the service virtualsForService := getVirtualServersForService(allVirtuals, svc) if nil == virtualsForService { - log.Infof("Change in Service %s does not effect any VirtualServer", + log.Debugf("Change in Service %s does not effect any VirtualServer", svc.ObjectMeta.Name) return nil } @@ -307,7 +307,17 @@ func getVirtualServersForTLSProfile(allVirtuals []*cisapiv1.VirtualServer, for _, vs := range allVirtuals { if vs.ObjectMeta.Namespace == tlsNamespace && vs.Spec.TLSProfileName == tlsName { - result = append(result, vs) + found := false + for _, host := range tls.Spec.Hosts { + if vs.Spec.Host == host { + result = append(result, vs) + found = true + break + } + } + if !found { + log.Errorf("TLSProfile hostname is not same as virtual host %s for profile %s", vs.Spec.Host, vs.Spec.TLSProfileName) + } } } @@ -334,8 +344,22 @@ func (crMgr *CRManager) getTLSProfileForVirtualServer(vs *cisapiv1.VirtualServer return nil } - // TLSProfile Object - return obj.(*cisapiv1.TLSProfile) + // validate TLSProfile + validation := validateTLSProfile(obj.(*cisapiv1.TLSProfile)) + if validation == false { + return nil + } + + tlsProfile := obj.(*cisapiv1.TLSProfile) + for _, host := range tlsProfile.Spec.Hosts { + if host == vs.Spec.Host { + // TLSProfile Object + return tlsProfile + } + } + log.Errorf("TLSProfile %s with host %s does not match with virtual server %s host.", tlsName, vs.Spec.Host, vs.ObjectMeta.Name) + return nil + } // syncVirtualServers takes the Virtual Server as input and processes all @@ -371,6 +395,7 @@ func (crMgr *CRManager) syncVirtualServers( // Prepare list of associated VirtualServers to be processed // In the event of deletion, exclude the deleted VirtualServer + log.Debugf("Process all the Virtual Servers which share same VirtualServerAddress") for _, v := range allVirtuals { if v.Spec.VirtualServerAddress == virtual.Spec.VirtualServerAddress && v.Spec.Host == virtual.Spec.Host && @@ -410,14 +435,16 @@ func (crMgr *CRManager) syncVirtualServers( ) for _, vrt := range virtuals { + log.Debugf("Processing Virtual Server %s for port %v", + vrt.ObjectMeta.Name, portStruct.port) crMgr.prepareRSConfigFromVirtualServer( rsCfg, vrt, ) - if len(virtual.Spec.TLSProfileName) != 0 { + if len(vrt.Spec.TLSProfileName) != 0 { // Handle TLS configuration for VirtualServer Custom Resource - processed := crMgr.handleVirtualServerTLS(rsCfg, virtual) + processed := crMgr.handleVirtualServerTLS(rsCfg, vrt) if !processed { // Processing failed // Stop processing further virtuals @@ -426,18 +453,15 @@ func (crMgr *CRManager) syncVirtualServers( } log.Debugf("Updated Virtual %s with TLSProfile %s", - virtual.ObjectMeta.Name, virtual.Spec.TLSProfileName) + vrt.ObjectMeta.Name, vrt.Spec.TLSProfileName) } } if processingError { - log.Errorf("Cannot Publish VirtualServer %s with invalid/non-existing TLSProfile %s", - virtual.ObjectMeta.Name, virtual.Spec.TLSProfileName) + log.Errorf("Cannot Publish VirtualServer %s", virtual.ObjectMeta.Name) break } - log.Debugf("ResourceConfig looks like %v", rsCfg) - // Save ResourceConfig in temporary Map vsMap[rsName] = rsCfg diff --git a/pkg/pollers/nodePoller.go b/pkg/pollers/nodePoller.go index 35f142f8d..098d7f6f0 100644 --- a/pkg/pollers/nodePoller.go +++ b/pkg/pollers/nodePoller.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -23,7 +23,7 @@ import ( log "github.com/F5Networks/k8s-bigip-ctlr/pkg/vlogger" - "k8s.io/api/core/v1" + v1 "k8s.io/api/core/v1" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/client-go/kubernetes" diff --git a/pkg/pollers/nodePoller_test.go b/pkg/pollers/nodePoller_test.go index 788ca7fe6..09b890af5 100644 --- a/pkg/pollers/nodePoller_test.go +++ b/pkg/pollers/nodePoller_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -26,7 +26,7 @@ import ( . "github.com/onsi/ginkgo" . "github.com/onsi/gomega" - "k8s.io/api/core/v1" + v1 "k8s.io/api/core/v1" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/client-go/kubernetes/fake" ) diff --git a/pkg/pollers/pollers.go b/pkg/pollers/pollers.go index 5ed3dde22..e729cea37 100644 --- a/pkg/pollers/pollers.go +++ b/pkg/pollers/pollers.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/resource/resourceConfig.go b/pkg/resource/resourceConfig.go index 94793f2d4..ec3a904db 100644 --- a/pkg/resource/resourceConfig.go +++ b/pkg/resource/resourceConfig.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/resource/resourceConfig_test.go b/pkg/resource/resourceConfig_test.go index 64e1d1eda..20607099c 100644 --- a/pkg/resource/resourceConfig_test.go +++ b/pkg/resource/resourceConfig_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/resource/routeDomain.go b/pkg/resource/routeDomain.go index 29897c981..fd8b30d01 100644 --- a/pkg/resource/routeDomain.go +++ b/pkg/resource/routeDomain.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/resource/types.go b/pkg/resource/types.go index 4121f3335..dc60403ed 100644 --- a/pkg/resource/types.go +++ b/pkg/resource/types.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2016-2019, F5 Networks, Inc. + * Copyright (c) 2016-2020, F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/test/configs/as3_route_cfgmap_declaration.json b/pkg/test/configs/as3_route_cfgmap_declaration.json index eac3b37ca..0106f9694 100644 --- a/pkg/test/configs/as3_route_cfgmap_declaration.json +++ b/pkg/test/configs/as3_route_cfgmap_declaration.json @@ -1,9 +1,9 @@ { - "$schema": "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/3.20.0/as3-schema-3.20.0-3.json", + "$schema": "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/3.21.0/as3-schema-3.21.0-4.json", "class": "AS3", "declaration": { "class": "ADC", - "schemaVersion": "3.20.0", + "schemaVersion": "3.21.0", "id": "urn:uuid:85626792-9ee7-46bb-8fc8-4ba708cfdc1d", "label": "CIS Declaration", "remark": "Auto-generated by CIS", diff --git a/pkg/test/configs/as3_route_declaration.json b/pkg/test/configs/as3_route_declaration.json index 1ab21cc3b..d0709152a 100644 --- a/pkg/test/configs/as3_route_declaration.json +++ b/pkg/test/configs/as3_route_declaration.json @@ -1,9 +1,9 @@ { - "$schema": "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/3.20.0/as3-schema-3.20.0-3.json", + "$schema": "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/3.21.0/as3-schema-3.21.0-4.json", "class": "AS3", "declaration": { "class": "ADC", - "schemaVersion": "3.20.0", + "schemaVersion": "3.21.0", "id": "urn:uuid:85626792-9ee7-46bb-8fc8-4ba708cfdc1d", "label": "CIS Declaration", "remark": "Auto-generated by CIS", diff --git a/pkg/test/configs/as3_route_declaration_overridden.json b/pkg/test/configs/as3_route_declaration_overridden.json index 4e68ccb25..373f709eb 100644 --- a/pkg/test/configs/as3_route_declaration_overridden.json +++ b/pkg/test/configs/as3_route_declaration_overridden.json @@ -1,9 +1,9 @@ { - "$schema": "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/3.20.0/as3-schema-3.20.0-3.json", + "$schema": "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/3.21.0/as3-schema-3.21.0-4.json", "class": "AS3", "declaration": { "class": "ADC", - "schemaVersion": "3.20.0", + "schemaVersion": "3.21.0", "id": "urn:uuid:85626792-9ee7-46bb-8fc8-4ba708cfdc1d", "label": "CIS Declaration", "remark": "Auto-generated by CIS", diff --git a/pkg/test/configs/as3config_multi_cm_unified.json b/pkg/test/configs/as3config_multi_cm_unified.json index 0bbca9aa6..1e2952c3f 100644 --- a/pkg/test/configs/as3config_multi_cm_unified.json +++ b/pkg/test/configs/as3config_multi_cm_unified.json @@ -1,9 +1,9 @@ { - "$schema": "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/3.20.0/as3-schema-3.20.0-3.json", + "$schema": "https://raw.githubusercontent.com/F5Networks/f5-appsvcs-extension/master/schema/3.21.0/as3-schema-3.21.0-4.json", "class": "AS3", "declaration": { "class": "ADC", - "schemaVersion": "3.20.0", + "schemaVersion": "3.21.0", "id": "urn:uuid:85626792-9ee7-46bb-8fc8-4ba708cfdc1d", "label": "CIS Declaration", "remark": "Auto-generated by CIS", diff --git a/pkg/test/utils.go b/pkg/test/utils.go index 39a7ea3c7..e91e56197 100644 --- a/pkg/test/utils.go +++ b/pkg/test/utils.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -28,7 +28,7 @@ import ( "github.com/F5Networks/k8s-bigip-ctlr/pkg/pollers" routeapi "github.com/openshift/api/route/v1" - "k8s.io/api/core/v1" + v1 "k8s.io/api/core/v1" "k8s.io/api/extensions/v1beta1" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/apimachinery/pkg/runtime" diff --git a/pkg/vlogger/console/log_console.go b/pkg/vlogger/console/log_console.go index 8d7d85734..2c0c275fa 100644 --- a/pkg/vlogger/console/log_console.go +++ b/pkg/vlogger/console/log_console.go @@ -1,4 +1,4 @@ -// Copyright (c) 2019, F5 Networks, Inc. +// Copyright (c) 2019-2020, F5 Networks, Inc. // // Licensed under the Apache License, Version 2.0 (the "License"); // you may not use this file except in compliance with the License. diff --git a/pkg/vlogger/doc.go b/pkg/vlogger/doc.go index f61337d67..63b914f78 100644 --- a/pkg/vlogger/doc.go +++ b/pkg/vlogger/doc.go @@ -1,4 +1,4 @@ -// Copyright (c) 2019, F5 Networks, Inc. +// Copyright (c) 2019-2020, F5 Networks, Inc. // // Licensed under the Apache License, Version 2.0 (the "License"); // you may not use this file except in compliance with the License. diff --git a/pkg/vlogger/log.go b/pkg/vlogger/log.go index b70addce3..b070d8f40 100644 --- a/pkg/vlogger/log.go +++ b/pkg/vlogger/log.go @@ -1,4 +1,4 @@ -// Copyright (c) 2019, F5 Networks, Inc. +// Copyright (c) 2019-2020, F5 Networks, Inc. // // Licensed under the Apache License, Version 2.0 (the "License"); // you may not use this file except in compliance with the License. diff --git a/pkg/vlogger/log_null.go b/pkg/vlogger/log_null.go index b66c9e38d..6265e7fe0 100644 --- a/pkg/vlogger/log_null.go +++ b/pkg/vlogger/log_null.go @@ -1,4 +1,4 @@ -// Copyright (c) 2019, F5 Networks, Inc. +// Copyright (c) 2019-2020, F5 Networks, Inc. // // Licensed under the Apache License, Version 2.0 (the "License"); // you may not use this file except in compliance with the License. diff --git a/pkg/vxlan/vxlanMgr.go b/pkg/vxlan/vxlanMgr.go index f48b95b13..57a3c3196 100644 --- a/pkg/vxlan/vxlanMgr.go +++ b/pkg/vxlan/vxlanMgr.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/vxlan/vxlanMgr_test.go b/pkg/vxlan/vxlanMgr_test.go index 111fa7c68..479ba3fd3 100644 --- a/pkg/vxlan/vxlanMgr_test.go +++ b/pkg/vxlan/vxlanMgr_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/writer/configWriter.go b/pkg/writer/configWriter.go index 7a78a9c95..aa5740a76 100644 --- a/pkg/writer/configWriter.go +++ b/pkg/writer/configWriter.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/pkg/writer/configWriter_test.go b/pkg/writer/configWriter_test.go index 0a39e566a..b4e0833c1 100644 --- a/pkg/writer/configWriter_test.go +++ b/pkg/writer/configWriter_test.go @@ -1,5 +1,5 @@ /*- - * Copyright (c) 2017,2018,2019 F5 Networks, Inc. + * Copyright (c) 2017-2020 F5 Networks, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. diff --git a/schemas/as3-schema-3.20.0-3-cis.json b/schemas/as3-schema-3.21.0-4-cis.json similarity index 99% rename from schemas/as3-schema-3.20.0-3-cis.json rename to schemas/as3-schema-3.21.0-4-cis.json index bba0d4be9..2ac706bd1 100644 --- a/schemas/as3-schema-3.20.0-3-cis.json +++ b/schemas/as3-schema-3.21.0-4-cis.json @@ -996,6 +996,14 @@ "type": "boolean", "default": false }, + "cacheTimeout": { + "title": "Cache Timeout", + "description": "Sets the cache timeout (in seconds)", + "type": "integer", + "maximum": 86400, + "minimum": 0, + "default": 3600 + }, "certificates": { "title": "Certificates", "description": "Primary and (optional) additional certificates (order is significant, element 0 is primary cert)", @@ -3258,6 +3266,14 @@ "format": "hostname", "default": "none" }, + "cacheTimeout": { + "title": "Cache Timeout", + "description": "Sets the cache timeout (in seconds)", + "type": "integer", + "maximum": 86400, + "minimum": 0, + "default": 3600 + }, "ciphers": { "title": "Ciphers", "description": "Ciphersuite selection string. ciphers and cipherGroup are mutually exclusive, only use one.", @@ -9527,6 +9543,17 @@ "minItems": 1, "uniqueItems": true }, + "serviceDownImmediateAction": { + "title": "Service Down Immediate Action", + "description": "Specifies the immediate action the BIG-IP system should respond with upon the receipt of the initial client's SYN packet if the availability status of the virtual server is Offline or Unavailable. This is supported for the virtual server of Standard type and TCP protocol. The default value is none.", + "type": "string", + "enum": [ + "none", + "drop", + "reset" + ], + "default": "none" + }, "shareAddresses": { "title": "Share addresses", "description": "A user set boolean that indicates whether the virtualAddresses should be added to or checked for /Common instead of the tenant. This value defaults to false, and so will put the virtualAddresses into their tenant.", @@ -12981,9 +13008,6 @@ "type": "object", "additionalProperties": { "$ref": "#/definitions/DNS_Zone_Local" - }, - "propertyNames": { - "format": "hostname" } }, "messageCacheSize": { @@ -16644,7 +16668,7 @@ "description": "Maximum number of response octets to buffer before deciding whether to apply compression (default 4096)", "type": "integer", "minimum": 256, - "maximum": 32768, + "maximum": 4294967295, "default": 4096 }, "contentTypeExcludes": { @@ -17885,6 +17909,11 @@ "items": { "$ref": "#/definitions/Pointer_GSLB_Monitor" } + }, + "name": { + "title": "Name", + "description": "Specifies the name of the Virtual Server", + "type": "string" } }, "required": [ @@ -27796,6 +27825,7 @@ "type": "string", "$comment": "IMPORTANT: In enum array, please put current schema version first, oldest-supported version last. Keep enum array sorted most-recent-first.", "enum": [ + "3.21.0", "3.20.0", "3.19.0", "3.18.0",