From 480420b15d35125167b9bfafbf789f8edd8f4454 Mon Sep 17 00:00:00 2001 From: nicholasSUSE Date: Sun, 2 Mar 2025 13:05:16 -0300 Subject: [PATCH 1/9] cleaning release.yaml --- release.yaml | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/release.yaml b/release.yaml index 1f5162087a..8b13789179 100644 --- a/release.yaml +++ b/release.yaml @@ -1,3 +1 @@ -harvester-csi-driver: - - 105.0.2+up0.1.23 - - 105.0.1+up0.1.22 + From 252ca16626aba338fe60194502b50a170f14fadd Mon Sep 17 00:00:00 2001 From: nicholasSUSE Date: Sun, 2 Mar 2025 13:05:22 -0300 Subject: [PATCH 2/9] fp: longhorn-105.1.1+up1.7.3 --- assets/longhorn/longhorn-105.1.1+up1.7.3.tgz | Bin 0 -> 32117 bytes charts/longhorn/105.1.1+up1.7.3/.helmignore | 21 + charts/longhorn/105.1.1+up1.7.3/Chart.yaml | 39 + charts/longhorn/105.1.1+up1.7.3/README.md | 50 + charts/longhorn/105.1.1+up1.7.3/app-readme.md | 27 + .../longhorn/105.1.1+up1.7.3/questions.yaml | 981 ++++++++++++++++++ .../105.1.1+up1.7.3/templates/NOTES.txt | 5 + .../105.1.1+up1.7.3/templates/_helpers.tpl | 66 ++ .../templates/clusterrole.yaml | 77 ++ .../templates/clusterrolebinding.yaml | 49 + .../templates/daemonset-sa.yaml | 188 ++++ .../templates/default-setting.yaml | 247 +++++ .../templates/deployment-driver.yaml | 135 +++ .../templates/deployment-ui.yaml | 186 ++++ .../105.1.1+up1.7.3/templates/ingress.yaml | 37 + ...king-image-data-source-network-policy.yaml | 27 + .../backing-image-manager-network-policy.yaml | 27 + .../instance-manager-networking.yaml | 27 + .../manager-network-policy.yaml | 35 + .../recovery-backend-network-policy.yaml | 17 + .../ui-frontend-network-policy.yaml | 46 + .../webhook-network-policy.yaml | 33 + .../templates/postupgrade-job.yaml | 56 + .../templates/preupgrade-job.yaml | 64 ++ .../templates/priorityclass.yaml | 9 + .../105.1.1+up1.7.3/templates/psp.yaml | 66 ++ .../templates/registry-secret.yaml | 13 + .../templates/serviceaccount.yaml | 40 + .../templates/servicemonitor.yaml | 40 + .../105.1.1+up1.7.3/templates/services.yaml | 47 + .../templates/storageclass.yaml | 57 + .../templates/tls-secrets.yaml | 16 + .../templates/uninstall-job.yaml | 57 + .../105.1.1+up1.7.3/templates/userroles.yaml | 53 + .../templates/validate-install-crd.yaml | 35 + .../templates/validate-psp-install.yaml | 7 + charts/longhorn/105.1.1+up1.7.3/values.yaml | 531 ++++++++++ index.yaml | 43 + release.yaml | 3 +- 39 files changed, 3456 insertions(+), 1 deletion(-) create mode 100644 assets/longhorn/longhorn-105.1.1+up1.7.3.tgz create mode 100644 charts/longhorn/105.1.1+up1.7.3/.helmignore create mode 100644 charts/longhorn/105.1.1+up1.7.3/Chart.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/README.md create mode 100644 charts/longhorn/105.1.1+up1.7.3/app-readme.md create mode 100644 charts/longhorn/105.1.1+up1.7.3/questions.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/NOTES.txt create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/_helpers.tpl create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/clusterrole.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/clusterrolebinding.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/daemonset-sa.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/default-setting.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/deployment-driver.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/deployment-ui.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/ingress.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/network-policies/backing-image-data-source-network-policy.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/network-policies/backing-image-manager-network-policy.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/network-policies/instance-manager-networking.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/network-policies/manager-network-policy.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/network-policies/recovery-backend-network-policy.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/network-policies/ui-frontend-network-policy.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/network-policies/webhook-network-policy.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/postupgrade-job.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/preupgrade-job.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/priorityclass.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/psp.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/registry-secret.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/serviceaccount.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/servicemonitor.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/services.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/storageclass.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/tls-secrets.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/uninstall-job.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/userroles.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/validate-install-crd.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/templates/validate-psp-install.yaml create mode 100644 charts/longhorn/105.1.1+up1.7.3/values.yaml diff --git a/assets/longhorn/longhorn-105.1.1+up1.7.3.tgz b/assets/longhorn/longhorn-105.1.1+up1.7.3.tgz new file mode 100644 index 0000000000000000000000000000000000000000..e05df9adf8db477d2de966c1b68f3b0a1dd3ea33 GIT binary patch literal 32117 zcmV)pK%2iGiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMZ%b{n^nFuMO9J_Ux(p4i@Min`eu&gWT2k>o@>zHmu$a`q%y zHrNf4h?@s zM^nsYZ;og2UpD>p`~Cj2{eAeq-|v_I-#ysh`OD7!^MmJm{r>**-M{pA_WFCfe?k3? zV^Z^ELSp`x{;k_8ckWN};3Q!ZOUe>4=pYngiDNeDg;>g%^eEfLnPdS?gv4OYel`<8B?d=Jb(`?iW*=*ZMCf8RQs`hMA zj<0*VcqRxBSt3ayp=Owb<8934HRG4tGpwkfhU_;IN|A$A(6&PsGw$96>RkZudTBE0 zT$1@U3`G-nw{lFZT=gV3MEY=mQ_a6CdmfG$`}I4B{| ze8M6k5RPMZO(F%2X9-e5K8Q#fvpI=S$Yv=^NFoIiSvW;lEi8lY|$z8YocNUIDQrh$4+q@>9N$tjk)*Is8#?^%K{I@9V6 z`bopG`bW;Xn@8z7Q}C%H2SZU`empLjfOa>p|QguC$??MA4>BoK$k>yH`jic z=$daxv;F{eLG#OBlku2@a)7#T*m*c5Q5KW@BTH2qYBahh|IBdQ^}AH%n%noPzyc19 z%UqR$PL+ER=@B=hnAfYLyyg+Jq%Fh+A*GARy#4_Blzjmx405s+o2^o3m6ml`J&mFx zSKv)yhE&J`7CgKNe`rY1^FRWph#k(|W{hanLl`5f*k ziva5i`W{0E)#0!M*z%@4tM39 z;kP}boHI_Mz_vzNP*yU1p2U-OZAm9MR|i`y^v5-gNeyLhfDZK!`m6KPrJ7PMUM znXzO}RhgC@{8m>%P^Z)i`e{lMlqDi1Avk|L9VZh;tVO=IxhhHOO|J%u+zqM~?#R-V zarteQL^1h+%Jv+hD0iS8hL0gBGV?(vy|%hc7omh z?m>UIzYm|3YO9SNW0~Mqqys(D7)!3=y%JF&9z=jaz%2%g$ayy?Yr^jKcJ>Spaw6#O z?fCCZ7rj@q8T1wrYEx)gdA+mO+tC6$!Ks)sS+;W<$a9_-zgH4@Xf7htCehQRdfw~z zc8k+9rdK2(LJT<@Ewv96R*;RhTIRz-uudpwsaiCWo8|lE_X+5Pn5Nn3vXm zG%gKz52n9%L3t2;pMmlEoesNOsH+yJA>&g0{fgn}TO2D>iL2kn!xs!SFF{k!zv0%<=2a!M+jX5D2%!tTqLK3vs@AvyaroG+g&z|?37NJ@kpd^dq zPRS#%geGP%dbjPAg>y$e>vlVxR80~gNumdRng2?7BE*WX+zilLnMW}eFab;f_&q?9 zXU<{ulE%b%mVtU~yb{Eh;sS_DZsfiNIlCMSlwyu&L=rAm1^N1NEQYGK@aO9pNn;vf z6tXOltAd2z2Evg7FhG0GV}~V1F$-}_<-8qWf0jj5fFDpzq!AG^Amg!`XHW9hRSU07 z0|R6$w_n)dY7tQFz_?rPOM>T`rn6nvT2?2%&(V8$h)w5Dp zRiH|q)I!sSXnL{cM4K*}7YK)GrQng#9HpFG!48c>0$P{cxDAw4zvfgDxo4{@wdaS<2SV;X-X}}g|{aVr) zfnV_b8VfXI5r~&3Fx5e@n7-?2p!ec3K_XxaLugJyc185wkRjQbA=Z(m)c|$X?C*M1 zMsHr8qnVyoY0hc2tPfw#e)@k*gQ9~_G8Q?9bu~j}oYQ3TcQz_+Y_w!4-A@Aq{l-Sc zO$FRM-K|&N-;J`9Y*ldRBoP@W8qa@bOcH@GH#83!=OmQz99;vqXjyFG=d!Pd9-nAc zZh$`g{IQ$h8R-tXBOG34shWsXe8*Xqb_Z%yKK=SZufD&r(JLyX*|7BedF=?934*Y# zXY@*%tVOwR3qVS27jlBN4wgj9IF$@&Y?xzFlX{jVtcawhuu}`Sii?~Q)H*0eFIB2h zZ1kmN`JOg@NjQvA!0ZbiL4hnIS#Z=h9i zy(I{(k=U4HA;OC2xk)!le58<1gKe$G>z3zjSSQPtl)jY^k2u178kH zdU%F^X9>O*5CJ6Bs$Hn^OZU^)W+vvnAG!_}XmE0ql2DQeoqvBA9PI3(a7w~Uk#N){NE zoD0;#lU&WnmcSAl`$f1dV_1_6PH!rE?JH0(scdiGj(XMY^7W{vgAZ;+Jrnu3HO4~L z6R;(na36zZudY8cpCQ9x%gvES;q$5iU)A)hdGbc`5Bpr)hm zsC=6WBv=e_4ZzmFvC)Z*fbi|fw#ZsUEj2a5#*`5fb7>c-%3k|1CNq{O&2`8k*GFC4 z_Y1{><%YwD3VnNd7e06sOX<+F8A&36E(u91U=8;v8kjzqFlqp6h|w{dYCw|9Y^01T z#2HhT42O9&U(+#ZfSoZWk15w{L$iT=bbg8s&5qa_4Wh^0z3vm$tld^C8qv!e_x71? z)xNi_wJHi`%i&hdo1KkSoA%uJw`$(oH7KLdDMo_jp-(4Clrow~t#l|0*Tgazg)vK& z)F%Z2_2%Wdl2Avd`v1e9;J@#Vz=e4D-|x;&Ky>Nq7no0oPlh*m=KM$bQ2-=J$caQ) z2o_STR3*1oX+THKLYGy0@EZ~8&_wmSWW<)4c2*TSExa1?3Y z^K2bOLJi|MS7~3Vo{&hXM8cz;4Sh|qoE9`0SdSq*b;^Y7p^M7gp#pWcuQ1<^=_n8K z@AisrxgnO*n)V{!C)h)W6_3^wi((-}m9`JRoR6m97P5vP(}tf=a|LLHZCqgF$d(&t z#wXR}OI*lgLI-JrX;-Up3z&K}Pd6-CgI3Ckv z5o!fy=VYX}Aw-S~Og@}=dqY4ajRAPK^xA7G9A=W4y$r9-A>koOq%yhK*qu~z@wp=c zGzvi&aS~%mufS6<#XQoxH7LX>4q^1`d26TN2WB$B-(C^!);gL@ats>Ln$d*LvYFRY zm`HiUW=4{llC}^cHz6UBW+BNWj%x~S<;LGgDK|u@Wk_=e6wDGyV>Dx2Sr0gb4$hQv zmcvq$FB7DR8oLKRF<;WMn*kEMn5#Jc)}@*taR2&DjXN^+cZk7b!%bxYBgJbqjO7rW0H<(sQu+Q zO$p{sEEG1;%2Uv2p56@1bx>VMKA{$(#ZXFAK-|P{@)oon+c? zzNNj?+CuuE+j%=S3X1rE#+1a7^>h`DqIxdc^Tl(6u64ZF+OnoB{8S1_7w9hpog|uz zhCd3>0ERyv8K0qA+btPP3^oYsf@x&sVod`|q=2zuU87j7j<7gyA;Ay@c21cP6ihMe zpRM<>ONK@?i4aEDj9F>Y(^6JsA+)T zYL)lm)e0z?72bLv3`*pNgkYdIu36ojA}6-+1)UL=HEP$|s}C!5K_P}+HEf$UIu2-L z1*P6owkse&7fp<2Wc@=qc@@J!Z?yfTu+U1juY3Ev_!{59GMP&}k%7%K&SI}^(}F_G zIjI02y}7|*laxfw1B<3qK!8tE3%YlD1#{s1ow0LQOLgIU4ek}4QMs@?h6C@YD;4NV zyYUigtki{CgR6vXX%F!=zBwaOS%NHSLmm?~jdawscPvZuS#js3ku>>SE2yk##wYri zU_*1DdicTPnn(=dpSJQZ%BU_JLAeK4gsTXmK1ewv0#ViQ~Nim0&EjFG1aG8xr zC}Vxp>jM(=MB*E7OXZTxcU}O%oq;|o_n+$Bu70;`-hp4Da$4+vn$K6Z>r$&zV7U&- zDdSYm^S$Y|ge&M)iaDkvPHpf&T{SK6Mg&}dR}{8 zzNT>uW(S0qMTG-pjb}`AJx_^B2yg&hC1EHv9Y-Pb+zh`U63vOsW70m@<=uuar9Qzv zXvdoOW`O?Pv{<05QghD8*wYq5PGLqY+!|>1a_Hy^;*?Nr^u=+mqH0400WR}WOysql zvG(j<$dZJFc8R5GiRW1=N%X|?>w4$#bO54jOYiFI{RDXPt$QQks72X|2> z*}3lT+Fl{hAc(IL`tAbD?4vot_T*wrc!_Eec+CZoPk?~ritw6H9i^fe9~R0IyA>Ii zhrle>p3Z6P5b>mk4#9_SwH|GKdT6P&9CMkwJsi}0pop>`fJ9V%DM6A$c zVri@cmxe4-0=?*sd*^keX$-1yLw36XCcfuP$=xOi(3?k0nHC=MV1l+}52FyCJNR#t zBLh+imK9jWph!TI_I*3f@hO>c15wWj^}ABRu*l7evU{ip63(on5d(E#M3gAdhRNK3 z-~>ryMfu=NTTsTGt;IAEH4VX9Ou_4`qiIwvvE^^hm{4Ee|0!9@Vm6ugil>8B-53As zzaj3-^GquW{8!haRT?#GE#(d-Rll`&tIqM}ZEiP`xRnR4o_`Dohzn>&bLa&ZMr7!X!`sEhZ{uhLcRmX?s8|DlKfz zg=vL_wz5^(*QTo3q>HrR5^5q?F|e++&52eA9oOYfbEoQS^3X&`f+Gdjb0~OXL=!L~ zAmSs>D{a1?ku)X=6(FB~!c^9n*;Reralh}F4Oya8f09V;AkJtk3!4kDf8Yw8Sp-zU zXh^t{Rm;r~J3b3q27@yy?rT{6S{p8nwu5K9`i&K9m%Rab^O^^=U*JsR(a^C!UyN+G zCP=pXxuRqjpCf7KA#ELLTRm`6W3Qwv@{W|0543OD5ELCOsSlJKou8VMhdp#O#mPjU zUU9L4g(e}q(%2x-PaSUoYflvutEyEDvmuKF^k?WDUs)(QO-zm5-b|v(uB>%wPVtrH zK_?)rYNKlDtq!UebSQih&5~59P z=Y!EywOpvBSY(!QW#B1IHL{B9k%F0}=K$?H3(STNYzS40S&l4N3l&$=Z){Y;%lEcv znN)*XRl;gc^*roeW~G9pwShndL8}Q^&9dR_jAox!Zt&SS*dkqA;E~yuwRkdPQeHcw z+n;Q9H>W764=rRJ$YnN=8ie&Sr*6?zu86P3#SCCEj#LXk6G81}iBV}`YfRg;P{RdQ z*cfs%unp_X#|fhf%7S6AyOU8Q1n zv*a>i*GaeBlQSd98@f{5V)V91^{ygV{71ug&X+GrQ4Gc{sW%WoT*F73n8Y4L1HIRE z@y8t<7j1LfIK{ouE58fY{ch>QND$-c6epm6n&5G}%)_w?k+LLm`fAbdAS8}+kIa)E zdRvACV`%hS#*yJ1o81k(XJv^1b4@MqsUm^K?$CM^if&D_3+6me3OSktme`Wx@tB6~ zV!ixrRa4)9^|r6y=rP}PqZ!92OH5p+(>`s(+U8I_N+w4v8B;!kG76sW zk=ENm?%<-V$=9SEFxF^4cftCar)|ydH(e;%-RpO)ENPkp-*k0KEd}1F^h@@o>cfwd z$ZBKxk~hU-YR{+uOVLDz(=uOIrurbmzEE~IW#98ti8?7xBbKK#hHnbAz6#YFXAZO)tv| z#{f|1>iuj{vd61yMuT>N6ZHMX#Sn!tRpX^~41F{}F9?Fz9cM*FbUsf)1nV+)8WT$d zjR<$7$u|Wcvg?X?&L~4l1xtbYUdr?cnyyNnW%^KQFW#v4M)=m40ENxkFotL`&(7|d z{C(e@4UZHuZwtu0ViOdTD-s(lXcEy-SyZ6h*h6uGToF5oV>SWJuzHfcUJ{=sW7aJM z1rKpT!|oR9zQhv8>W>r78DtLl33E7343*$m@hF?9KQ1^9_3`4EO1Gz*jrR-uaVN!R`9syo4SjEVRqai}+GnxLwoGv0??5g17hwD$(Qf z;qeboG%psR>fFRi#i8UHjR}?+H{3mCSsa;d2zR6|}2eXo6HI zxzq$X(9x_u(%-FNkkssej1ifoa$Y(<=Nzzl2gy2iq5g>~@9+3)r_LH}77sj@+EgEl zZTg2RTeVp_*yII@vKX9^IAO_r#xk{LgRQHEMUA3iSET`Rc185|Nybwqh=0mYz&RuX z%^uM;u8N;+yy}@YnF#;&@uCFx#_ z>4;$-A=mOufAY^GnE72n*Dl~r)6xP^_tA6A+XF0iW6)>`VhiONhE9hFN0C|$v;qbL zbfoDda0AWRY7};?l|;6|dpc$SJr-$n z`Cd-s6I*DpxO=tInqS3d9OH@DEI!K0Z5;72C**fym3sz(S;yemUW&P-u(}v^6XzpH z-5vpG!2m4R^DzQjVl#587CItIOya(aa&aT)1X*c(8m zuFG_9PLSmXhbrg6-krVDTa@LhtDU;5$*^z#e#d=oekTY=IMh?uZ7<^9KSXiCHBO}7L6v^F z`gYyv>n-cjh2tMT|N6lWRSZ7D5xXL~6(v=&M4zfQ@sP%$Ypzy;9-EsSF3DVPnbu#$ z@W{K?0sgly8!mNd2u7`1!+u7_#dP(CwdVScda71)N3^Bu$4|GTs}7P1F3EgnfV%pJ z4({!izV8;l?>h1wy1V3>^WU3nh2ZJae;#@_&@Cd3cT?R`@Eayg-n6BU_ohIkV#(c_ zlDpkp0_pAeMFPkL((2TZcO!pHRKRA%k4bWT-_oaaca9fz_AeoZYyd}lDU=WHCWKI1 z@_tTfo9w+|errXt%|TF*#W`H(TDF-up~>clxh3Io_SFGBNZRZemg_ zpyX$r2j+sH*7<>K%#XcU2m;`ERI}W^JM|ax(hWy0kWE9;)5mS$7el*kOQrL|xxWU+ z(TmDH%`2F50{SEk^%{fxB5=PJNn?FdoRn^avUexxV=?&}?cBr!^O%ytnP!tJ6=q+# zIWR0tzrSZf`Y6A`N>V;Ya2~@XG61ZnOvnKeBBp7NvQB&7`o*hrB`!+C1X3Xu| z6+<#FUY#$sE>&Az{CgvXtS#tVkC2Wdkg@2LPmfywDVEcoOFQUg$nhyOnxiqZcXfe} z2ux-V1p4?<4f>}~fBX1R{r>a`))7c9vR$4yx&|azL>J8601JMdYs~c#Ff6GKRotq{ z3k3UgN}?zc1N^PUqdC8=;OktC^@TdVF#OsDiosRPF_|#EFAPW4tfa(IG|;t*^G(Jg zz@eHaHV4=vUF;?JGl5WW@Q{u31Mrq|p60)WQkaBD5F;cnAHPvp|P==Dq6s!6jPnFzI286qw=MI1z9&hK!v(;r7_CoN6qZTFxeK&-yV7= zNbb@puBVwG`btoCo%of6UTi@c8LZ7gSq*1UW=Ng?S}|oUIL9qI_Jj(t7 zmoVI0Baw`Y9U`5zn=Me!w!L zJ2^alebSq0*$)Y4Xrj$p%8W^iiq~L!LR>46N(D84dT0zfotCR&$|B8+RL=8TA0H3T zhvJD>4JHANN#PVR1jQ>}hN$?(#|KPIpHSLqQaUWT)7w1&ni_RPNAl-s(J~s#fF@|j zA~jDnt~i=eVa{~8!;~%?q5fldK6ER!riam+*%jejjgq@S-zHZ!63cOvAmc1H`F<4I zu?ut&NMxe`M%D#b8RaPlYq<;59&y?qWgnKwEhvakya~$_N zxa5Db7it`8xBZ~%-O9xXGm}SaM#j-!63GD5>~;=vx7TZy(B;`>VG?;xbBuk)e|gIqGIkIkTbuRj)sS&z$Q4(iTR3%0 zH^S2FQF|ao$Z=|RaLhQEb4*j>r4&T^KsZE(n@esAfv!4EvjW|QlWF+6Eu*~VVPwdB za8YA^14njW)1Jrzy2A~7Os z#KO$!d3hK>>M8`*Q134l6FrW0ge?euIiNeFl` zZJH~?AyS)2Ok=}=c}J}WV`YLcdm1)X@6C=YO(sO>^frGoifHaUE77I%=uv*Bl$Bwk zQ@CcTm3^hm5eREbIWytDn#SL;BlQWA@@is#&inse)Q`KJfBVhbi<9%7ypfw~qu=lMpY89% z|NVZy{C|J%VD~RO`_B)a@Adop&v*aQ-`PLd+x-jbZwi4$Po{LVzw~e2R=IP3lE*PH zsAJbQ+jkzFY1Gqy>vW8MevPSACOf%y=hMb619)9R9D7Rj==>B#&QB_~Y}nzccSyAy zuV`~V(S%BhWBR*VPdh(SK_yZaUqO1S)!)i*Kg})3?9V#OzTBr~{=c7+I3-;4WEyXz zjV1Gc@A=NN()>Tzf0+OG^L+fc{S;l%*+6?1XiVfhB`;=*Ea8+4(9`WtpE{~k=j0}} z3%u{%20O3UG35etb|_!rdvKQ#3i8k3q3j(&J@D1{euTVKP}16a=no`$mW1fp9{fpX z=h=8nZ%{YLfsrJFzcqqK<($~#Oj)e|%y6tPy1;2_0)u`c8akAhstwf*NGF9eL6Bgx zV$K(ZCgdsAhXZ3eqb}Pl73lFutLMjW&Q)2ZCMc`<$s)Qa?25Gc3YrvR%sCTB#ZCz7?U5TFc7@Kpfr$Y~A+Y5#EV;iMa*U8?K3bsmE54N}eDy*+` z@E-^Le%AxKKGNEw)kUQyKmO9inVgDWx&!p_m+oKfAL^z0Q@{H3=~LGcycD9?^Fsa5 zwru2zi0ag&rAB>v%UTO2mS9p9-Pu2 zt*GN89QM>g$THG9F!H|PWirxb3z1iv}_BsY>II)%PQO`m<#869+~FcXr^>`R!p z;Eom@gsuo5nPT0i-9iiK=Wh4c0yOkqGq;fIc&nc>tgX7(cl^hr$o)EYhJf=cc!QeC%RZuRUs7B2s1+>3Chrm)aM_7i_Y6HKqk*0x860jVO z&T&;c+7T5zgRP-a7EKI}YB0>^n%xIn+D3lL&@gIEb0$s@_T|eUuc5Dvq&8VU8eyC7 z7W9_QrX>v;-k;t_8%*l|?R~Z`eE)Cv8Jy4gW1#DEH+gINcby=CKfDiC@in$v z?K{8mk|yJJ8G1IX>eHu1C~l8w0)9H~VN-lpY2E*9FfbNQsUb1NywH)t3$N2A_ft-_ z!iz>)`=$J5>fSfBrWQoQLkm7F#2`!cCZ7Y~UXeNU6pFVf{6W9G{Y}DkyH(BwaPT`FY8FYTHLxmTWg7!v=>YGMnRu+=F?OJv#y>2U# zLdJMR6JPzRiY6V1x)hc@W8Js{8TCdBk5v|WY7DN$XyTMQjimq`z-}S4%2nap2$oi@ z%rXf_AFs)1%GhNglvocSj%l=@NMpxAsUTPq&;sm=tmC_@SU0NARg{%}tY;XD$%sN4 zGriE}wpYXJno(~fvV$P#+>Nf!!ZgTZpf<1iE1kk3@F~AR<*Qc z!ITCzOXeAkwDxWBFH$!X#L(9)NT1tW+xWBC{x>{$OEOC}TT^mD^mdwh6WRDtsx!R!VTG9_QWEL_ zdvlyu$J8pb%><$wbH51@I|T+d7}xb$J*)Tp8{dW1)TnwCNC?TbYn6Wh%)uy~^UAAA z_76OZo0=}U(=3(LV~%qX?f{lg)szrLIss5=`@gt7tj6NwN7ogo&?|?K^f*bGpm3$+ zr%!|BlC+q3vNg8ldUa@nkNFO82DqytT&Prst?@Z(JnsN&|5k-nk*}*;OYwq= zbr+=f?_K?Y%J$?hSFA&S^Z4FQXqJdu(Vim<$M4@9zCQ7Q zL!N_|oXv{74q@2F4N`fpak08PgxNJVbv`^ix`Xy~>|kA^r^Ai3rgsv1DT_RSww*U` zk54v7NM$Yb5*ERx$!+-OySGPge>^!mK0Pbr)t+;50YCz!-Y-w*p#lNCYy3!r{{7#PhzUs%P4q3V-Cqqz6C+SI`3jOt_Xmj6ef)3`+y! z^S4}|d#N|~+pHHlz|hA)zj?ECov~RI3aequ*l?53#Np{C?0KH-#mC>9J#9f&Xi-9K z;jQ<1t+brbuYk;AAb+5LW=xXhI5A$1>Gw1DH8oaOrg$XankEsuw%4>(qqzJ$f@J}Z zlV~-ltqS`%>!^O~z*@ETAIP}7p7{c^M&sBRjWxdRc-HNJ{b4)avLEeP$Ioimh)Qjt z)tIM{J@J0Hr-1e9>{F=j=>E;R{Ifct7jn?*;Ho^dxG$9##cVfkmTl{0X@n&?mmEtn znd>pu-p>&+Lu#G-T1D^{DVwd+d4}exS(A#pB~4^=ZkV9P#gZ01F*;aP zdp!JNC4!YvQfv*WJIn~$-wXRuuJo@Qs&yw%-TtqZO@Rqbzx@{Q;{D(Ke!r6c<9Ywt z!NdOVeLS_YSSMh5jnhSuEhRQtM})2^-z`FQj5Mj~wlts_q0dMj+~q;Z}1u!soPH(kojp@@phAl3x~h{j*or-f~7vNPuQF_w6U<;rV-r3tjy-o#V#tTBKO)r-h}w=E`qoN>1pmBftwdA64cIhoolv*6!oFqk*I&gLLB>2v>@(d^R=zW zx6tkYS(|O{T$#q9xkniMt`*dCmj;v#EYq8$=*zp(+}7qbJvgN}WN~cs+Ln|&_#UJz zj)OdB?Narw0(Fy!>s+_`0?CVuR}NwQKCsHET#RT5%H}D1aznyQQkIxZyk+f~*zbX~ zsd|^vwG4B!S^|ukR#$y3R(RTiW(T7b7xd-DoZSq3vt2NN&ojuqI?iI%#P?J+K8KsG zy}nrFg)0pG2&TGt5bK+<7xrptdw0^kzq8S6d~-&mGM-pc(o&j%@?9wC<5#BAaiP(RVv}g_LSNAW(GOomt;z=Fy{fy}6e=Q9CYFbV#-m+- zUu?K-KT%hKCb#2+YVQ^g&5O2>m!kevxq=<_cJy6>C$QOXj3%i2pI!7AE;|ZkrO~|q zo0@7mSA^bxiH=+z<2T;6+uGAl!wzf;!#qneczptq-$d6mD}6K;PRZJWpJzU{plFGU z+jM@t`MDY{8=A9iSZdikZs_|OO)a0;NgeOB7?MROH_hjymI#|r1qzWkZVKABElj`K zc%Y5=!86IuaeU=FnZVm8^vlH_?Y#1)aXN<7CPNneG$l#VNB%A$Hz^4viQ;(?XPplv zNLdtIPf1et&Ig%Sb7{v~Vz5zX0u@TMox6-}Z<8a&BbI1~dhSZl<$^r5TfmYaG(|yx zFLop>Zs!i1%m2+1veY&HJ4?u#{_#5achHSvDlV6H1GZ4s>qZ^?O?E?Z#xc82hAaa1 zrYzBM$4~rNhah6t3CyC%6bjO6=yGe=8}9(ev>t8sp*5;Gl+F4Bm56walMKi4{7`Cv zp~Z(#lEh9l&o8LTC`Ama1lZIu(o1MjW+(R&2Vu*`?_g@2ku)X=6_A+hCro9hii1u}!X;0j;ewvll_$saAZ>`=gY5fk?*E6E`^I+$~+pDq5DmUNtR>+b~n|hcV z^&|Ou^pHj3w0NMT$)rnJB+ThsIHS@+FfMCq;}IBo@Q=*Bf}`a>HI>sKGWG11C|$ZUv;qQ~)^3ktf|D#g2XcRBE=h>aO^V8*QXA^B=0eKA zUa1fTHlyWIO?Gi>chooEi?1j5;_ell(?+nY+QsHZ??!SS+AEax1ybe^@-pG+E?%}d z66_}NTJm!_4x8S*vM1*a(Q6m`;^}`o$n6*VCGFf*m(B{MM#o9xvj z!yG4)km$6STHxJg5_75^?j~{9D}d4X%b@^fd9X%Bn?Qg%cpGH| zvz{JfiBI7cS6@G~Uv+#Awci)>MIFRDNBML%BN4??M_V0^CE-?8u*%@FUIo;`(9vB1 z+{^5A7N?)C-uo8F-8q4d^c@yUiD2%!SiO^`fz7%iX6%YsQiCE#+ zsIqRfL=a^dySy)z*D3MbUshQ@1;zS zVoDNOmV34bYAgaVPr_g-Wg3J~xRn@O*3>4u6|-dW-P!O+fqv`tLcKRf)mva(g0fiz zC$GpAi9O6FL9E^^!AMuzeC*p1o28sUmZH~0PFYkAehc#g!3;{Yh<>X;y$i&x)m1d^ z9NNytTW-PCLcD{By(XNk({3fC>tSvZ>#H5LN@!cw;d-^BmmRI$EX2^Szfrt)>+srb zkJs+qPfYQjrZh;#R@)6CN|>yoxl_FT3_W->QLwk=K=1SfTJq9{PKP+ zZtpJk*^S~h%=n~cbKNSusruY%Ki!9SS9AQkHh!Jbl)sIer)}GJVUWDWH^s9mZcJwQ zro};(GMu{_lUHR0t3>~H`c@spJH+^9j3;6d#$#1r6^sGmMhzZL$nPXKs9rK&*+kG~ ze6wxLc)N{*1>o;$!^eRCX-X0uU!->_>bFE-GCfR!>7a8&xl_Z}h_R5)1hf z)0ka(d#U{T#_rRBQ93pS7HgMvAgd^U?o0&_&s{vV`9JKHtbxAt^R^j4mfZiaf3RP< z|7m~!;r^$4c^2IN;Mibc77*Z&K=aHxw>GSu1;pk$vKOol(9Y_YKUC4b$4elpjTf(H zpb3>nl`9(Z989nU+ISVg7jsvGpThKOG5vZAeI11AUr6SGenwwC4l^F3V1{;3AW*<` zrqCpdV-#GY?q5GnrA*(4EFzz}kpFtHyHTaK%et-LF=L!0^7pS}2?|0F!|A``o zAW^C!6-_4pX>y|OsxJxo+NMOUUW8GTH?wZIzA!?soAkEkl8c4cT$C=laJo#*RTsy4 z30Zj4Md_}Kil$`CXwsX3DAsPs0{ms<-7jL8@wo712}65j3yHIr=d*51{M?-SxouYK z#rdXh+i-o>>AcPJld~UBk51kn9v!`X_vT{LEmu<_Ryo~rKqx4LFT_NiF(ymduXB`t zc=zqetCNfOXK&wLyf0?Kc6qQp###opc7oI#>Cz0UpqT*Y0y8ftRS_+=BS+__?+-67 z4v)S+IeUNl`tZA&fgh|s=bBKgn{PFUc5g)+m#StNdHjM4DKtEL`{U{P>DxCOCsG5h zO?0Yad^=L#AKk z>M|)+Y2ennvyA74Qg|7P@#97+OGWxu9h(7 z@2zf@sD*Jy7fYD79`2R6yL%;SNWAv75;d?s)2$K)lZQ(s?)XxPIy$d^r$imJ`@T{F zExMPNXUU;>CkP*)e!Zk^Uf&uny1Ms!m_GL&&!T7X{$EBnaRL0Y{l90=o|W%^KY0F- z|NmZ|(qv*ONyL}I|_ zirHv;hLz~t4p|~O9c>F5kr3;x=FTIerxL;lYFLSajL?8pfFvU01W}2uX&j?W5G1Dr zX@t5^uj@ks5kpYOl0@IBi6ny>x```_5!ST}7u3KTug{d_Tcl@D`c7`F$*9|F^)$kI z(yx6}zGPb56>s1{sItoo*hssHDhZ#_#GJC>gd`!Kr}8sh?c))u`fjCt=*s>2_Oclq zr&C;H0r-?mf{<`&E?5XENWf)zme!RUbc)#8TXdQRTYW`;xHW!%f6tP`ziy|oHn4bJ z{To+*(e*zWg)#M3GVjlo0|&mi5w8Xi)Yx9{PVK1{QAe<)0S0>J++R$AVJ1I}V4*se z(FTpoB~Wq=r7ZF@Bo#CzPR4|D66wQOd5WvkNy6M~mngaDDYzzdGL<@f!vo18+tLN$ zmEAlbOVvuS4~)ynjXjwnswDz+N#?-1l}`w2rwVNM#R^miypWao))o_G1%k+|x#T5g23bD5~myMI67d8h5RfeiY(R1tSuNe}t zyoIW7xVBEouML7L7NiEnZg-K9R*9%M9lv36$cZ4{&G^f1sb5_#+sE9Jn~h?cUv`W6 zq|jObC-p>tqewCQi^00>DNx|}jR=3?Y8F1bw`IBUV!2Gw5VBNAPVnr73w#K1tY*OA zo4$9MzbYzY0ZZ%)xWre+V%zxV)Ze|3%S!1>GOsUuN#=#ZA!C=6n6>-G`N`4Q$wgB~ zF@N!~n=c=OZj0rmyVad=mZjZ6F3TzFZgn{kEaL#iTwK-N>Ru5(>JGX(?6{i`NV9*{ zcc7N~TaY{TT1f-HS6(zJE4P^9jv7iJwG6DuXn8`f8|hR}P~A;5K*@wAH$jNQsZYi7 z75?yj8_I4s!hk!}76E|*^-u=r3iE(x$%6VkOSW4Jpu)_uOrhqVd)W|M^y=-K@4kO~ z_U8TT!#9WDotzc#u+Mh@7X>kO7r}jZ`hNKKtafLltFZ3YJ9F-IL9CxGtuM-6d5#f% zwu}$Z$DC6&DpiJTQ{3mhh2@KE_UGGPd3Sodt(8jsJK9!xclxlUa)(2@l8FDB#_)CzEtvnEsiYy4-xhr=3#%6T%CndlfeT)~ zIxy;k#T#4+){4V&TJUSQ%ciZW*6mh+rQRjeIhYH(j=P$tvot0%l4#-Z0>Kb1{|B%6&0hjpo8_+)Gt!|c#%IvcVD%gF7!Flvg* zSmefe{Z`=TmSGRi`cKXJZ-l(gTu+JEE@ohcgeBUA9TbYrn>2;KN~^L}yt-+jKb zxBIaE-^WuDDP};2X6V<@1KxNL<~7ej`;+ zo$g?SqkcVhhfRYjDh=pV6%+r6^=fb$x>n9PwK>Q|qTMlge@q_MoQ*%L%YS=}y`Aj; zOB?zBtStWl5k2n0pY1)^fA{lzX8E5BkIyapb4(uO{)62AKjvv8|0~%mz3Jb^Nw`%0 z@0a5LclVz?d;TE*@8h|5`ClWR?qBrRAn_peAEf^OflnLxzq-a>e3r@ogJ%aN`M>w< zdH+HF-^X+B^1ns|-l6<&lDdBuXGMMiN)nw4K1T|IbGzJxtz6;|L)F3v*oqw zLa;>s_n-B5O7j0;|3Ux1pXc+*|1wwIpCM3gc`;ILmkKWgKR_vGl7%cDpo=3LFt5Xl z{^Ov(_XWvHAc0bSp1UgbU#@o#G&0<6)A=#6%zRlEN%fD7IDI9 zB|WDU_vG30kkEm}aUnr-wTAUq)MHa$rwMx(JK2)5yDoHj!K&14 zsI(G^FZaZshr$}F9b19Ww(dr%A?t}piG#ZR?a|F6kt%Gl+d`G5BI zcFX>s=lzHM-+OsJpZ*`Rq0KrR$%s2_)t-Zv* zD&Id4AMEsZ%lV(5J>PlI|L^0ekp?Lz@AUW| zO-Xo3c<(nhIw?tkY9Yfj#+rb)C9lz~?F&veYhG-@uQ8@EiE2!ZLUaF8mPUz?_iAWV z+Wynq8I6}0fIfRgV=^Jp07;&ab#0RxqAki~sOAa_Jv{v6fm0^rw)(#P#h5t_H#HPG zvEYUVzcYVci|N5Sd9Y3%tdj@pKd($Rl(I;m zDZbLz{Y>d(N`!QdV1`b zQe#i!IA+&F`~F0PI5t;PnF5^rGozeD$DE}{IK?9xQ%P;m$(xgl_h*McSwJMJ7CHaN z`TN7;*Qakf+6pznI93qom#4#{;)~(wagKt!#Sl~}p2cK<&eY4pWDZG7U(qDHY4|!8 z-*J|uO?9)>rm>5moM6;}m{H>^ix|JUSencKnR-@Ixnv>zL@9-$0nU zEOW{tuLLsj5e|DelT*g&?=TpZ1?7yzWC^zfT$Q;+?#C5fb|z0@fN)B4LI#HQfsypd zWcNO@o*x@3si;i&$P~x~@oFi9-h3#`i8YD$ElnbtOqS7bWQyG*8Cgt>8^{uJL8m(Q z_PH}X*iCF8vXSCE7@tCl>_g`eNtSs`R_w@8#2*SfC8U@DbS3v`!-bHrqEtoKif+{V+LO^K;EU%5A{Jf}u9wl@ z1WP)$C%y8Q(#D3KRaIG#|9PL|Uo-!W;52gc?)QIp_x8&6|MULC`M>*l7G2nCSG)x( z#;q6GTj(XK!ZnrCa(aD(b~SHyZN_iw0A6^lz_P1tTTrU@QoMgjVzs@TtL4R9rdYz{ zy117d*+uy#iWmFpyD&M4;97UM)|4b6QOnT`^Z5XM{jsZtzB}l?J z+@keQ@iedhGnP=v_&u!uyZaUWzrXj8|KnaBBVFBWoDs=s=w{_>!vt1v2PKu>FbPd2 zy^wLj1YG-HmPiK5LSF@EGa{!X6G4&xZXukUv{>=RkQGp?k!KAQ#8E_*5W}%PL08;X zZI)*>>p-jKHn*Nz-|LDupV#E~syR;Rykh32iWZ|wk|<>~k>2sZ0rF#}+R}(7lJF}W zBX_5Z{;loMTJpCCE<%n|azST=W%*qj{>zOt!wIl5O(u?`yjO$8EcVSU8`rPTswh-G ztbxeGLVh1l^ZLKJ3&57H{|9CJ|KQoqga7Ydo<)Yl-CQ@>c<%p>asyQFcPuVsx6KPs zx=paQRN>e^D%~#V*QoBL-Or#jr46{7%mS+n$?91JN&`|?sE{+DJRV+!&ovwkx$*8K zd)_L8v1;bL(ooctDWt_Kj|7x=g+I5b{Fi*{)_=)3o{)`&|1CZL)!(ng|Ls3}i2u2l zr&hKdx!{mRK17dA?$Lv2v8izB0Q~_1#E578`N&`gu?TsfqyFf{RiLGZrmT%yHlx9; z^KmJqV-tZ16bRsRagS3WBqTVPO{v?vngRH07z0O`EKex79Azc^;sKSGGl$xVtA z;fFveqcDsyo!L;uZUYvDV(8N+eRZjh95N9nuUSL}=yWzC5yetNPcg?cBE558`qs*~ z<1>=RG{mC0Nx$Q!^byMv=~`Fx#W6A8oblY<>)Y>R&Su}@@G?sWsM~Eg=~Hd;r6}I& zITrek&?T6a4hjC_PU?HYi_?#uiCKs zwY>3UEZ(Mt`)m=)-!(U0sJCw8=DvwjIM1iunmHE!$HtjjfRMO5Z_D+MvBdh`@{95f z@{Q1q$GND8u-7nk#!VS2B@yk0Davo z&8i@OW209TuD|`d2}?z&S1iOamGfl+``9a6pMqquBsiwxva!37_i?FEC_obVnW0;V zsW;wnp$c+^16<3HD?qv>a-7WA6**6EDyB?|<4g_lOBxfM7W9Hsj|H=2hSS%WU#jv) zQ%sXHs2(j^1lz!0i>y>A8lDlooWnXtcwxM2zAqqd6TGg+$tTH#CX1FeSEjyKpIb$J zc<%72vHxT&Oz7u^T)@lXKM$T)?7!Xp2mkNAJRj??l=lL4R0)og38@q^OtM~>XRbK4 zw;aD(#d7>=shh1fu2aUs*_bjGy^x!Yx{z>5$27!}pg+*)**-}^WUt-t!QC>d*d>`4 zJ_kYYC10CgGyk&$a)`(AhSLAE$p2YB|Ml$P;359wUY*?CB_^Q9&Mt<(Pn;he>r3jkZ9|3B~VKQHV5{oRNBFZc4S zc=FuL(T3Ce-9lte(k+EzH^ax12`3XQNg$c7J3w8@Gt#X)m5+Y*lwr!c=-0yGeDrhI zq&nzsA^YdHkXUB$hJdfr|I_=(&3>i-xA$2PDQPk({OvxM)H(wl^enG6{o8}7ghl>` z_rYG}Wz^Q%ca4pUDdvTmg%@5cW-BL0v+$x3zF*33rtW=1Yl?Zype^`Rs+^^@2$xNhqr9Ok|7U^1RgapM2!^Pt_BDEw$<1bx;^ zANA683U7SKu)pDTsPLjvP}wAmlbSb;$Y}CmDRDTRkwkh^)O%^G|LXE-s44$cP4qRg zWwe!9B%*Rnk)^6WNUR5m^&qhxB-TAjtSd^c*OXYQ>Vw33kXR2A>p^095^F-FDjib+ z|6gMnPSxE1+-B;-b4O2&|K|$FG*Zii-3AVMbSqcT693QMekK3!^XCuuKi<#t$oNes z5csvsOzaHUDWOB>;3zXAK(#qFuxkJEQ!$I1&U}Wy$^y&`_b1h zY--W%Z);;+yE?b#nsAI?_I5y4t-ZUgW72N}W5>W)x84P;x$D-}#|c)it)mIo?69u9 zdc9MlwXHqYZ&ldD^lNr zBDF?!(3#eoM7H*s*0@%$uIJC8Q@U2CdeaOv0eOC|;@;u#)EJq*(xQAj}DZqq)hXhlUX5gN%*>3Ee}+IT0y?V@j$D3a6M$6KZ6Os&8^ih5p!s z)oW?@{2!lt$=>L*NdHSkYIVT7)c^Vi2c`YL-F|=X;r!>lJa?i0eO!=J{*jl??{TC2 z>V1y|>K1d(Z&$L-cb_zzd!eIR~|S2ds7n6=pGh~RBqj9$e9obn=}iEjS+;~ z4?3NlUQShWsxt`CkrL}6OC)D;O!&6hc0)0n&=A>vO{kn^BS_)t<8FBgY~ACB8%HKTW|pY zam^lh-Mlp!Zz{0l0H0A4=K53wMgC6dk*AJ0-OsnX6tckr-&d<>T_psStU&fed)^2(8V zwby(8w=G0u*n6V**sJ$nFVy$l9mQ9#@g+fU=iG-87Sj(~=tG$CSp7eyNi<8O`g6ib zs{Y5F--H2Q$1SfCNf1rCXnd{mMX_MX*TE!{q6Y?Yp39FnLF<5m zLZ!tnl!-o|2ot5xP@yQLL@Z+M8b&V}N8kN$vIQBpW;2pRBtq{-St2tvJti3u61_b) zoGYlB%v4(HiXyH!Rx)a?W#2m|W+n5RR@6TDTc>j_F_$nYlFH{T^z)EK$XaV?Xl_}` z1##s{4zV4wBqXU6+xBjz?UY4<{bA0ZZ9mcWAdpla_mA{CQ=-t}@U++I94b-EiO6EP zg`Pe&_FuNBYfqn|$Be@OpfM+6>ef%i3{^_lv3RnDGC{a@cDbtyB~!ZanDH6HiU)!; zR*R~+5?qh0Gf!bod~jCx2k`7khCYC&?SrzusmwVl<>X4~w(;B*lsqFJyybN8^l9h6 z(CHY>S>_s@vy3}4yKZo;oecCjCSc7x1S&}Wmz1d5mA#U za=x69C2H;#RaXTYFqhEr_8Yz7vAX{TC9$Th0( zCWvgDrt!R3;9TM)!aNd2W?C)-R_t^x@+(ap_Ao>v0@`dC(g?2qi|09qk_bJ%p3-ot z=1Bx-Mp!D1Psk@*=vqw_$yt=zQ=r=aftT@Ir?xAxfXdD>H(9@?%<~)50YJD8D>n2D&^beMy5GPt# zIT)Exq_8ZRs%45M1*L>>^g(e~C}R{PsAQ|46w7dmf)suIu?y!nyEZ)T)7K~n0l_B#|aoibBLM1JY`xl+uq%q@! zqj#rUD8W~Bq6DsF=rBzM41-}OqWC_y5I-n-B*k|@$fFNx)J`1-0~Cozy$*y?4y`04 z=;xRwm$}$jq+CA9XE{yO8mbxT&*-h${Nt#F(=eo zwu99>tg@@*c}%VdRCKwiq!Vvo%qyE@G|$~N9>V&XLWOliB1q8^IXrT&2jD_*I5lvg zGh&{EQ_d2t0UMWvf~5quEvMZrvn-Z0jfpKKpbf1(xo===DTRsDVW3)cwUvr5r(`Bb ze5LF&XQPwI$a$Y|uCuxO-NvPE86URL!=rR*SVRTrmy)^r&GYi=7(v)K7p zb^Nt(`rWC^?`LpZqGJ|ja0jw1sFRDvgg9 znpVv#t001PQ%K@HK;3sD7rMFeq0gMzV~u(v_t=yI$im%PGGa_EEFGi-3EzH#Z=@T!=rO3Hm&kk|}PUb#+kEr7RYlyhYk1hyt+L2U}MA~DYLd}(^& zA=NECjgijLt0^ELPFG*lqRCaMr1v4uidZ+01fAQ%m+fdF@uWzEtDWBS-d;`jF7V_| z`gLJ2xMhd*?)L4**6fh4Hne7sekBT+I(IR!h7PwJ*IRdLL!+9}+l^>OR~*fEr>k}P z-RYf-Vn%N}f@^nVLnB9vr+IESjFsq-)dsZ^=CTrHDz)!oz{}*i<>=o@k2k~_!aIm` zJGLlB?ySZW#h9a&$WyF(7u--F(JfhF!yVla6O5{dJJ;fc`e>?FtWY23rSU{RO-X{X zM5H97V@jeeZ$DFzqPqch8{5*fzSX;6qB;_<$4g%xr8Xss{IiKaP`MTh8X$pA6%kxg zxvD5K4s?yinp3q1;|D75Mlh8LR%NJuuirb^X)T@ZvhTO!l2Fi|&bP6qYzhSpEP!?_ zaddu)Y>hjgU#hV~+gLkhQB{t0v}taEFQHtOL-u>$^!iH}eZOa%_T$Y*>rD1tWPd+B4I6Ug5Y)RDLcX$1LT5M6XGL1p zE{+GS7RN7zHmfk0Pm-pKcHZ$g-wz$?LdbqZ@6KLTw^q+yAvQ+Xf^?-OSH>(g4=c2TpiflXB{;J@hX+Rd$C-m7{p2yLn6~Gj?G@P4L7WkN~b$8 z;XpV|V@d=>HR>b9_TDl@>2hTo*Mz7*=JphQc43wY=`QtBw64^Is}W7em)FlbC%%rN zb);Xmdv98-Bd&&2LsHY9Ubkiozg5=^KOE@>%mq{shSgN7DLBAfjlU=Wpm911qZu@D zXC`V@2UQQ5tEC{23oyr-oRUP+5Cb_O-l~Qf8)T9{xb3hXVj-@hh4`nc2;)&rABN`B zx~P{x*K?+G7@7j_%^WOnB}8{r+43k8lFjJvq%NjU)FcDT&s3R}WK6k`NYWWG5`Y10 z9df8=KjW8(jtfDVQw-tE`SB|ksP6Hthn)>+sZQJ_Q7wjXD{D&~z(w4xR^H2OL}DV( z7?a187sjM!>`iIJ8IvfY9PT$-aYbpf!2V#`QD~uK+s@JzwaFjr`x8y##3OgRo5q1A zvdEBnPXjKZ(YDhJ-we=Bof2X|B0a6mDQn*+xCVjH<6pXazjU7%LM`+-a=-ms5y|tF z-6x$qAJ^TG%6Fn|j#|d#zE4USd--mtWR3C7QOL6&?~_WN!FM;5@-52EP|ILoKlesn z_Ff+ioyZhJ@16b)6#bdZu_NlWc~SmKVo!v#o}(e~8ZL`}vtN#@&%Lu$1z1XTPzL zJ|4ugr1$me)XbHmT3v7vSuJ|6@l7s=3<>R&Mz8S=on3_WC~v12MOUnxS6=nab? zz`AT|S+rD9#1dqRqrCiWn93Q9Ruo6N8Au3d^4GW-35e;dTzY=eWDO)RAOZ#A1(>er zF=QM?49-fa_X0uo;U{K&kiMNyg-!nHFBbk0(*lb6M5#hX_mv8Sqex3%|ESUZ^1Atb zj3pjoIrRtBjU<*BxsS!svt=NMqvCC~Y$)PD4hc9HIAua=PA@K>RG{wm73Tk&y)SK! z<3<+T&;AvNj@V~$mffZ#d+boGH-e%rzNe!@l&sx-oLGZZ=x$imKn+mELmvP44P+*+ zs_Khuappx>U&QXlnMfq^&hILD5o0Y!x7q)om^(1`_ON)Z3tq|QW+gnb2E#C+G#c1$ z!j8My7$7(?YXqfs@l)Uz=nbMSlnYyv(#JhgfKeQu?pl`txiB&~_Pq^Yg=&}ZQP)XX z=`kC5#2@)DE`)8yVm8yJ8FdaKZMzQqwBs{9YmQYTk7qNfI!EAHIWRH47MG%8t~qn< z$61H`NbupK=w?cIl@JSns{48&c-1U!V(2wN9{}x%_R|}`^h1msx#ufOi#u)`{ghW+ zQSJ8*h}_RC{XK`sb5J$r1T81EMvO18yN&RGN4k`@(3ir9l5xfOC6^Tp288yjVp%14 z2hH|_dKAy}?oyZ_14=cY3R4KxV31N|0VrJGwPtB^)@k2Sh=m^=R{5BJxUB_O?&Wu{ zALb+oxp5oK7TlDWdyf^o<^>RwL2~-==;$_lXT~ga_=AT>oA?9T$Q!BTl2^wb8Po6J?KvH7A{?{c9~!tJgpuoOk5X2lt>AA(X_l`bq4em9Wh)OzM|}$P7p+50j*or z$O_|RF=2tUY-WTgSzG7y;L#6zIsp=Ad+geFr}17`VJ<}(q549bgohhC6W=E}3dr}D zGIT?xwS{2DcTK?U1!;PivU31XBP0R;Llk;;35YKmW}`%s`3dOG*980HO_zY;<4+c% z_?)Z!iOzncbOLFMoFI2vAYf`?q%J-0>wdwI?QHv(J{dmpsF2yq5(Kf{{0=Dn(+4FXzEts>OeyGEo`R8wiST^$QvV^$!wmHE1 zL^8<5mkAS<0p~@Y1J#GhQ`Xd_F6Hb7b8g~1?`E_v`zxDCQI+0omuA^oLDfOabZ7KV zlw^;(*u5R({hViwV-eDY51m8wnug}tM%i1m#;!V>q;CqH^N~$HyD`p3fZx{2xk7?5 z{RQ*XOn*7CBvKj?P7{Q071_NGL%w1P_d4^+YM)iXG20yXd&sP264>opTMMaXDd70fVFTAx5K1C`KmMW zcA84iDo%A(ovKEdOJ4Q0bkKykHY{t@(a(kZYek_|Nv9pQbHy>82N>~ya{7y$EF{oU z`fl|NJUTib1s#A$e>yrJ9kN=Zi7-(K?3)vNypa=|aaoCy>bZS*okI2n{1nunatUbq zT3!xa!wA}?R4t~sN1zS(;rHKff*3CS`L!ro zw;Bf*-3}>^Llc&^*$r%@+w#U^0-Nw7uf)BFd!zmlG#e#MxE`n!PW8(+mo)Jbk?uHC zD-US;M!tPV#~X6(5JX7RK|D#ORZn%uol&S%5D-yTwg!o2#7##s0nE1m<(*`8TIE>_ z29{Y{Iq1BSZb3J%XiVK$COAkijj zrrnGSn89_5nrI^+Cwe&v^QVlu|JD091eD#s5V|dpk<4uaU?Pay05@pzBg;sXFQOm; z74ifoP{r3i1!SK#j*c83M9j*bY9<*C9@ceM)K7RLXsFW&I$_o5LBvJNM}^?(XL zGNOr&=4Iqz0EPQd9<&m50D1>Z+eOEbh9e^CtU|D?45df2yIx1ioU%`@Yz2b!WV~>}ZjW10P|NA2&N4t~M*t zI6?daH7BpCC>)|2B?`~rNXNyRwr)gukfi4< zMI+2oDws|di#*?FYeO1U$bjs95Uj`r)TD~eRC8b^JRyh#fv-$_6gtK76d8baaDYZgNbf$u!ij1)>d#9Lh%|i1v z1cTDD+kP@B;8qhuQnVB)KmwX1fhcGv|K;u`t^5CKCAKlRxpq4k+(tcvo0GENCssAO zxuoL-=YZhK&X)owoRrjvuWwrl@uAC3FT}^+K?Qls~*bfg7WdUJD%{ zZUp)7lLx`Cjjna2=Qoo)Ip-Ix#Lxc|CR2&KkUQ}I^{bz(g9)Usfg+0FghYzMFR+}a zH-|w4bf@@F!HH+me%=Nrz{BH?Mp*Q*xT6skAa$?Q2p*2-%euL7NO&eH@H|GG&Ym*Z zGBiY+wQtIjwwoE36lOCfU^qY~>xc7<3tfQQT155%5kQ}oAJLgDl-f+;#(@@=SCPZCSy|oNhxN)MUvUmjTAW={yDI- z39Erwnkft;sprAK-sekw0FwakTJ%~%!QeKKTy5poW2KvgRP$icN4^U*%Wh>>G~-&A z-Ji>_(xG23bhF4t;Hn(#lDG?GE7^FshRcB?rSNwy{ekZ5_}~x{=Qi7PNhL<|B^;%> zwUj)3TIg?4>EiQvrp;JfN?7n{-H&5A8~XxqW4G!tt+v-|i-vIhT|@e5EbZ7fx~{#G z2(`N6H+Bq-yJx(4s`a)o#|^)s-0c)vQ6lNG?&5kjGq;I>C#>(~BQi=Nc@}Sc)^jrj zOqJ82cKE9JUsuFiI?+ zjQrsFWS)46QWm-78_bS!nA(~TsQ3s>;dj~_GgM9uV~QlR>S0p8lQQ@_#+N8M=!rbD zjIpa=l1#%N%y?)&QFb96uo0lUP@4H;W(AxUsG;B-*o|lou`mI*u_%a79G9WTuM_s^ z`2E|{w=bWtXYbhCcOTfvtK+vXpR*6IPS4oc^A8_R-@as@PCvY2#~(f%pS*hhjQ#TN z^~X2Q&-QQTEQ|!Tz?NLJtN;K;-v>Q0z93|#2IJn9bFh}L2NWMIFe=Wb9$<01_Qx9DcU6$SNqhio*qI1$gc zMK||SfNsLmpnam!jHqr%DD#JCebt&$R2(WfRc`NIujCHAnf} zeTsXeJ3!bFYax+waqq~z$;W%YrF;$<83-!-v4Vl5^OpNn)kgxM_}+g%bft@O~ocGZL@~eqmeD$De7EcXRp3B z;^JmNVTopSL&;5fRk1508<7_OfjU`Up#tznI|u^ylIla|VUV?P12i($i9R1;%ke_+ za(sP#J(0`#`3UQlKM0}E}cipHBqjIX0`{k2t7SD(uBDZ(hjW9yx7*S^5 z5k-FAmG%1WoNPsvz1U3eZ@A!>o?67(g;W#J^@7uaE30QAtIhoz6;E8>w#M7=QYZnn z5PfLoYFi@p^VcZ!WLej{7?MN%vIMQ?VVd9@f~enNDu`Qh0#+rOeM;s#!Zr2yLjGWT z(B{F##9e$P@Oo%Q0D~pA=a%!EzPMjlM)oHF39FWnlm8a%S@dzBdM7?U;1(PjQtreb z8sLmle#WVVN{cC@hPc`@gvwxg9&~FW<}Io=v_J=@{6PJTKD^PdREJ7(Uc-<+KcTGW zo;kg3{6&4LdqVhCl6{_4-rtT*lKmzh(%h@r4eI8g`#`HB5FtP1&PC}+%*iMTrV?~B zfgZPdX4i}6JAm>%@ow9}(zo6Lm|M7rm-L z>w+7BOVACkd^8tGKPS_VN#)HvAfCMXD2y!BU+(HP!6FsT;FpIOi|wmOB?MUE6$1;0{8*$OwzVkSMu*mCqrT!qD=SN3{6HZ_B+_O_;s!^- z3a`FyD=C19TpptKLaIi%=D0zF7zgV+auEIgD6Zt45){8Enw1M@OMb(Yz=z=?R^N^g z@9Mm>N8of8)Fm;{@?`qarj8MoG{lae>vp~fPHZayaR~gYUltlW61TTB&|O!hu+56i zS>3t+1y?ykp(~O-I*Clc?Fs9iMsy%Np0HyQXWa&%cVePz2A6}>!mGO~-YPKEGz+07 ziM~%-Hm~#ruYxq|yU4i$g$im}(V{aWDOyw|J0JD$_j^QOM}<^44Thp}ob{MwvfNn- zsabi5v~Cc({t)_$*62wY5g^zaI^pIZ?*Sqy%D{1@jXVGQ(EYE91^vG3vifKPjji+? zd}301`dZIf{4)27alcjWH+r6=!ou`OL~m-UKJR2w*?@m|rRP8$x-8kMBpat{rblTe zr_q!vS&REVpQKFJTL$>!VuiJ2RuRB3cb|(edf>**|9Ci6k zmiv+X>Zmb`ttsrfWDlNS*TP7s_+K5YPfd%V(IS;U7o_s=xjVD8Dr;BZNNUDojDwvf z5%&upY9p>|p{#^r{RMBWNYj%TLEhkjjmLg-(S)-87dKn1X|!!R(C#^gQ^ZQS>&{S{ zdcoDPcm2i?5jwMX@S7-+Z6l#*t9-$mU9=U`esuph2TgOKjS;ristg9s+^yO+JOS^) zB(5}LSjix&4I?JL!_o{WD=yZb+U=SKI9;AYZelCt$cO2;LA>)q6 zi*C4m{|s_m@LXC|(GBv(0Eb&poE{TuqrJ3aL2nG$5x|Qm=absHbkDZumB|;P>xQ!{ zD)f?buf+lM{a5o7t!C0JK|TATf+X|77YSRivJDS3sHdqs> zMzp!L!T{5R(zhdz#JNR=V!{|}kR|KB`utb-H9tk0j&P^P_mJACUgnY<@ zKxTRmFL!v5T*+rcCnpG`yNQdBAN8KD_~1!V2=7MRr898NG2*n7V_(VZabdI~L}CC} zN~F<`#RRe*RR@@g2UMv!HYahb$rxCP z%Wo0~G}kzQ&@yb!VtYm%Hq(LVdJsD|MlOR3PLFq6a`QRWltlZODw%ZejVi$V!@9@a zv$`M;H@ddoAep3C1s6=Wre#|-vaSRx7P2ahxUW}f#%;&ftS7m=;I{8x7F%s*hTR;g z6p^}`Mezi2v|X-3N%j=QKA_q`c|&K4N;fD$Vnq(+vBUUr#P|?md_KYlz$?1lGRLrr z-Cws`alixwhr4Gts(95j^+_d#YF2Uwdd6OT_%LPI%x%J-iyMTwQP`OZ-I*2o>-R?+fPt3b6TPgBuvTjIMl=hZTvD=J zCoNcLvbD#B4g4WlqKjm>B@DNRm!bOd{dSx6mR@f;?rt?0pP>O*n(?>Zp8GatC)9!F z*a%)G&VacmV5_2ShaCTIb=D!NP0WnAfii##;z|&B_s3mekVh6^n01n~p#zYb0^B`Rq}V!fjkA!vGj!NZZ<8l8#NioNTHP#l z>s~Ifp*nWT;Ye+C*%pmsMUB1`7?0MPT3h#aMd4mJazvvE5-y0s{-^huc#p~-VgB}D z(KNMv^4)iH*(}O{4AkutD85(55@{x+Et8AFI7nLkLjMy`77Z;kF zl7*R<_*0sZ`~aVj-g0UB=sbb=gL_QeZG91k5K)XTjyCxbx9_?dK*&qqRU2u!8(@DBW zN0x#Z_)J`iO4o2f{zEqG!P)fLe-K9Hqe8MoQ07Q+6}WPEj8WZ2nVkTgr1DqLJyt?p zN~6^hf~xwuyPYj`9j)5!)oI^!A_Mw6CZB-A+@oNedK9#ctmGGA*+Vey7Et*F==(y> z7w{cYCkMc$G4i5K64ctd{QUo#dE?*(MN~|ylrM88)#`bPaqM=7=nY2!&{x0_L&(Yj z##mLi&3C$O>b7AIPTw7*{@kdX`g<#lK<5CoC{S|32|Kpn9cLkEUV^w}!Giwq=;*&= z>}V;_`d9`)0G`ffvXJmn;O}PoNd3Y|v~-UGrjH6NeB!$ty}`XC3Xcfon_9v2=aB51`)toSIrvT`fl4C! zcYk%A$kjE*6TINIdBJ6+QJLWdpHKhW#~XlJ%D32LIRDTZ1qpKWTo&Y)h3tIEK%?je z_6}NqZ)Nd0R_FmUYHL;?${qJ#3uC2igertjTo=9xoc)y9n|DlV5H9;jmp#(CaD4#gNW)J@h3L-^nwG6U*MiHVwQ zV~{hnIe(HSpg`+^Y%If}fUf~Jx-zdThbzJIad`cxe%#$5HB7)^4x-06c}|dhgO!N2 zD&lY5$*+q7{I4DZI1mB&PmBLcG0Wis;uTPeuZUKFOP;R4hotOqPItB;SDi8kTNJds z8(HerP1pfOgNmtGjx+kFZ`ygM@K&cdKo-@#)uuC4@U~7whooi@A;tQu+bQ|AGjs;& zP+py=TgPaVS-V5s_m=vIEcp`|VkiLu@Q%cL`0;CQ_);{&IQ)K& z4s1`@umAb`Nb#i@JsBaNIXYw`Xv~bfAeH;UY6cWB=>~CS!%m| zx6B$Rb*2?0>0vKo#c<&gRrK7wr z$~pwZ3_l04v%AzTZoa(*B!_UbQ$F@KxJg>f!x^{D%3z88lFl@e@)j70wTkk9M+iOJ zCk764Raso;eW73mE;U$)>f5IoG&%xDbcaJlc7_sm9qdrPQaXn=zWhm%woKWOm>NSc zP-FoHBHFPUuTL8;zkJ`|*QrYanPG#mzd6&SCmwwr}0QmN*Zut_-RX%nk>6neQ7ipoD* zU#@}r&xX$)T!qDTtxYp_qWu_g?tHZUv8KRtu*=|lzenx1cLuxra8nQ6!e`z6-{O3S zkCLh==T$ShT8_*b*=TktjK7t5mxjjrBJt9Tk4*Qt?-w_Z@qx>SEwU6e zJ$yVLwRNRAh}2jFuY=bm6vw-ioP9ja(g$W0>=wd^3Hw<4@cUrG1eFlZDll}1EUp2j zZn;90Nh%@AEaz9A7}CKjjf|Ue2G8FWN2fn5df?XT)2D8KqX0`0k6A$ETim3TNsEF) z$)_j?Um*0u$3A7~CNb&;9By$pr{S#`2sun|X!0oC=AQl^-NN$~UFQD%?A=@Mn++o_ zd7X*8-~N6+YE5-MdU8JU&NVda7-k()eAmQ29vd;2T21(pf6jbxVo!^hPkXB8~LR$8yuSraDmiZp($w@Ug4*x{raNdhb z&JXMPb*(KVZ=;9nHNO#t{m5QxUiupIhK>E$Lnb>9gEL_+Wg*a6CFxH&*S*BL)r@zL z2s{)P+IFgejjm-qk$N;h?p|rzq=i2GqM$Gk)yg-M^cpRw2Yl7DB}5PGL3qB3orjiQ z^JdXm`gcRC_Sj4PnClnmEiZx#Pm%$VUEHvlcGuGLDYF(*Kg1!}@4vg<{qe{D`2BbH z`Hw#)D+tKyeV@{JQ{2j`T_*ftNFU(nIvA(jE-?-dYtZ&G)3~()yW$lCe&~!Q3=fD@ z;rTT$8vJu=#7tfjdDtRX{4&2kqYhpCIncr_Dc2w+%GSJ&9wkSnsLKHF){D!arVNVosaR|= zJ2lWcv?}3F67T6s6b%&fHA3JpK8W@4(b3TnZ1(Y^AOHH}WM#G#Xc#l5Kx_CIf!o2z zpZ&uB@sI8={WGQWi^s;owsFT9?&I-I&!*cvY@4}|T9?dB&@P&}VvIo<%sXa)# zvD(N>S&6I+0fd=5=^pZ!uFp$LGHCQ2O+x1%P9FUL=ODPLq!U!#hoGi}4B}((lA!JR=wWuK!l47OA2{R`!gwc(^O(|B~_`fd>)ToxQ$I= z1g2G(o}O+x`-D@4>X*sxx=m;~x7;D+E|?M;WSiOzt$b#MfKlkpk0%x0WS!#@_+4}3 z(Blbs4*T5!sf)FFVPw!DIoX4}ypxi1kN}nyt!?zuXN91GG!XE2As8>qj(=JgF0tGV zZN)=n_=vmUUPlYNU~c^LzhXw9c=RF;@jud{$F|hUSKJA85-=-UNQuln%R@&1->G4a z;qzmQPn-EH9)-Ui2Hqf2zZH1%vwPM5?ccf&Pjn*ba2FA*ZpP6Hj>D~Clzn`ZeEj^_ zc9j6@JWXHjCt)DKvFD@OGvg%5FRMxxb-QJjz}}R3mcUgJ0ju(5J$&@T(NLDavCsEF zzERLY&)8A)(aJLgLfVv}1cAVPV{olkcc_rf&%eJ9{qy_N(b3T)O_Bm(9C?= 1.23.0-0' + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/permits-os: linux,windows + catalog.cattle.io/provides-gvr: longhorn.io/v1beta1 + catalog.cattle.io/rancher-version: '>= 2.10.0-0 < 2.11.0-0' + catalog.cattle.io/release-name: longhorn + catalog.cattle.io/type: cluster-tool + catalog.cattle.io/upstream-version: 1.7.3 +apiVersion: v1 +appVersion: v1.7.3 +description: Longhorn is a distributed block storage system for Kubernetes. +home: https://github.com/longhorn/longhorn +icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/longhorn/icon/color/longhorn-icon-color.png +keywords: +- longhorn +- storage +- distributed +- block +- device +- iscsi +- nfs +maintainers: +- email: maintainers@longhorn.io + name: Longhorn maintainers +name: longhorn +sources: +- https://github.com/longhorn/longhorn +- https://github.com/longhorn/longhorn-engine +- https://github.com/longhorn/longhorn-instance-manager +- https://github.com/longhorn/longhorn-share-manager +- https://github.com/longhorn/longhorn-manager +- https://github.com/longhorn/longhorn-ui +- https://github.com/longhorn/longhorn-tests +- https://github.com/longhorn/backing-image-manager +version: 105.1.1+up1.7.3 diff --git a/charts/longhorn/105.1.1+up1.7.3/README.md b/charts/longhorn/105.1.1+up1.7.3/README.md new file mode 100644 index 0000000000..adb190be3b --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/README.md @@ -0,0 +1,50 @@ +# Longhorn Chart + +> **Important**: Please install the Longhorn chart in the `longhorn-system` namespace only. + +> **Warning**: Longhorn doesn't support downgrading from a higher version to a lower version. + +> **Note**: Use Helm 3 when installing and upgrading Longhorn. Helm 2 is [no longer supported](https://helm.sh/blog/helm-2-becomes-unsupported/). + +## Source Code + +Longhorn is 100% open source software. Project source code is spread across a number of repos: + +1. Longhorn Engine -- Core controller/replica logic https://github.com/longhorn/longhorn-engine +2. Longhorn Instance Manager -- Controller/replica instance lifecycle management https://github.com/longhorn/longhorn-instance-manager +3. Longhorn Share Manager -- NFS provisioner that exposes Longhorn volumes as ReadWriteMany volumes. https://github.com/longhorn/longhorn-share-manager +4. Backing Image Manager -- Backing image file lifecycle management. https://github.com/longhorn/backing-image-manager +5. Longhorn Manager -- Longhorn orchestration, includes CSI driver for Kubernetes https://github.com/longhorn/longhorn-manager +6. Longhorn UI -- Dashboard https://github.com/longhorn/longhorn-ui + +## Prerequisites + +1. A container runtime compatible with Kubernetes (Docker v1.13+, containerd v1.3.7+, etc.) +2. Kubernetes >= v1.21 +3. Make sure `bash`, `curl`, `findmnt`, `grep`, `awk` and `blkid` has been installed in all nodes of the Kubernetes cluster. +4. Make sure `open-iscsi` has been installed, and the `iscsid` daemon is running on all nodes of the Kubernetes cluster. For GKE, recommended Ubuntu as guest OS image since it contains `open-iscsi` already. + +## Upgrading to Kubernetes v1.25+ + +Starting in Kubernetes v1.25, [Pod Security Policies](https://kubernetes.io/docs/concepts/security/pod-security-policy/) have been removed from the Kubernetes API. + +As a result, **before upgrading to Kubernetes v1.25** (or on a fresh install in a Kubernetes v1.25+ cluster), users are expected to perform an in-place upgrade of this chart with `enablePSP` set to `false` if it has been previously set to `true`. + +> **Note:** +> If you upgrade your cluster to Kubernetes v1.25+ before removing PSPs via a `helm upgrade` (even if you manually clean up resources), **it will leave the Helm release in a broken state within the cluster such that further Helm operations will not work (`helm uninstall`, `helm upgrade`, etc.).** +> +> If your charts get stuck in this state, you may have to clean up your Helm release secrets. +Upon setting `enablePSP` to false, the chart will remove any PSP resources deployed on its behalf from the cluster. This is the default setting for this chart. + +As a replacement for PSPs, [Pod Security Admission](https://kubernetes.io/docs/concepts/security/pod-security-admission/) should be used. Please consult the Longhorn docs for more details on how to configure your chart release namespaces to work with the new Pod Security Admission and apply Pod Security Standards. + +## Uninstallation + +To prevent Longhorn from being accidentally uninstalled (which leads to data lost), we introduce a new setting, deleting-confirmation-flag. If this flag is **false**, the Longhorn uninstallation job will fail. Set this flag to **true** to allow Longhorn uninstallation. You can set this flag using setting page in Longhorn UI or `kubectl -n longhorn-system patch -p '{"value": "true"}' --type=merge lhs deleting-confirmation-flag` + +To prevent damage to the Kubernetes cluster, we recommend deleting all Kubernetes workloads using Longhorn volumes (PersistentVolume, PersistentVolumeClaim, StorageClass, Deployment, StatefulSet, DaemonSet, etc). + +From Rancher Cluster Explorer UI, navigate to Apps page, delete app `longhorn` then app `longhorn-crd` in Installed Apps tab. + +--- +Please see [link](https://github.com/longhorn/longhorn) for more information. diff --git a/charts/longhorn/105.1.1+up1.7.3/app-readme.md b/charts/longhorn/105.1.1+up1.7.3/app-readme.md new file mode 100644 index 0000000000..321e5193c4 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/app-readme.md @@ -0,0 +1,27 @@ +# Longhorn + +Longhorn is a lightweight, reliable and easy to use distributed block storage system for Kubernetes. Once deployed, users can leverage persistent volumes provided by Longhorn. + +Longhorn creates a dedicated storage controller for each volume and synchronously replicates the volume across multiple replicas stored on multiple nodes. The storage controller and replicas are themselves orchestrated using Kubernetes. Longhorn supports snapshots, backups and even allows you to schedule recurring snapshots and backups! + +**Important**: Please install Longhorn chart in `longhorn-system` namespace only. + +**Warning**: Longhorn doesn't support downgrading from a higher version to a lower version. + +[Chart Documentation](https://github.com/longhorn/longhorn/blob/master/chart/README.md) + + +## Upgrading to Kubernetes v1.25+ + +Starting in Kubernetes v1.25, [Pod Security Policies](https://kubernetes.io/docs/concepts/security/pod-security-policy/) have been removed from the Kubernetes API. + +As a result, **before upgrading to Kubernetes v1.25** (or on a fresh install in a Kubernetes v1.25+ cluster), users are expected to perform an in-place upgrade of this chart with `enablePSP` set to `false` if it has been previously set to `true`. + +> **Note:** +> If you upgrade your cluster to Kubernetes v1.25+ before removing PSPs via a `helm upgrade` (even if you manually clean up resources), **it will leave the Helm release in a broken state within the cluster such that further Helm operations will not work (`helm uninstall`, `helm upgrade`, etc.).** +> +> If your charts get stuck in this state, please consult the Rancher docs on how to clean up your Helm release secrets. + +Upon setting `enablePSP` to false, the chart will remove any PSP resources deployed on its behalf from the cluster. This is the default setting for this chart. + +As a replacement for PSPs, [Pod Security Admission](https://kubernetes.io/docs/concepts/security/pod-security-admission/) should be used. Please consult the Rancher docs for more details on how to configure your chart release namespaces to work with the new Pod Security Admission and apply Pod Security Standards. \ No newline at end of file diff --git a/charts/longhorn/105.1.1+up1.7.3/questions.yaml b/charts/longhorn/105.1.1+up1.7.3/questions.yaml new file mode 100644 index 0000000000..5dcd0f60f1 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/questions.yaml @@ -0,0 +1,981 @@ +categories: +- storage +namespace: longhorn-system +questions: +- variable: image.defaultImage + default: "true" + description: "Use default Longhorn images" + label: Use Default Images + type: boolean + show_subquestion_if: false + group: "Longhorn Images" + subquestions: + - variable: image.longhorn.manager.repository + default: rancher/mirrored-longhornio-longhorn-manager + description: "Repository for the Longhorn Manager image." + type: string + label: Longhorn Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.manager.tag + default: v1.7.3 + description: "Tag for the Longhorn Manager image." + type: string + label: Longhorn Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.engine.repository + default: rancher/mirrored-longhornio-longhorn-engine + description: "Repository for the Longhorn Engine image." + type: string + label: Longhorn Engine Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.engine.tag + default: v1.7.3 + description: "Tag for the Longhorn Engine image." + type: string + label: Longhorn Engine Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.ui.repository + default: rancher/mirrored-longhornio-longhorn-ui + description: "Repository for the Longhorn UI image." + type: string + label: Longhorn UI Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.ui.tag + default: v1.7.3 + description: "Tag for the Longhorn UI image." + type: string + label: Longhorn UI Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.instanceManager.repository + default: rancher/mirrored-longhornio-longhorn-instance-manager + description: "Repository for the Longhorn Instance Manager image." + type: string + label: Longhorn Instance Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.instanceManager.tag + default: v1.7.3 + description: "Tag for the Longhorn Instance Manager image." + type: string + label: Longhorn Instance Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.shareManager.repository + default: rancher/mirrored-longhornio-longhorn-share-manager + description: "Repository for the Longhorn Share Manager image." + type: string + label: Longhorn Share Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.shareManager.tag + default: v1.7.3 + description: "Tag for the Longhorn Share Manager image." + type: string + label: Longhorn Share Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.backingImageManager.repository + default: rancher/mirrored-longhornio-backing-image-manager + description: "Repository for the Backing Image Manager image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn Backing Image Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.backingImageManager.tag + default: v1.7.3 + description: "Tag for the Backing Image Manager image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn Backing Image Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.supportBundleKit.repository + default: rancher/mirrored-longhornio-support-bundle-kit + description: "Repository for the Longhorn Support Bundle Manager image." + type: string + label: Longhorn Support Bundle Kit Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.supportBundleKit.tag + default: v0.0.51 + description: "Tag for the Longhorn Support Bundle Manager image." + type: string + label: Longhorn Support Bundle Kit Image Tag + group: "Longhorn Images Settings" + - variable: image.csi.attacher.repository + default: rancher/mirrored-longhornio-csi-attacher + description: "Repository for the CSI attacher image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Attacher Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.attacher.tag + default: v4.8.0 + description: "Tag for the CSI attacher image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Attacher Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.provisioner.repository + default: rancher/mirrored-longhornio-csi-provisioner + description: "Repository for the CSI Provisioner image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Provisioner Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.provisioner.tag + default: v4.0.1-20250204 + description: "Tag for the CSI Provisioner image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Provisioner Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.nodeDriverRegistrar.repository + default: rancher/mirrored-longhornio-csi-node-driver-registrar + description: "Repository for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Node Driver Registrar Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.nodeDriverRegistrar.tag + default: v2.13.0 + description: "Tag for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Node Driver Registrar Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.resizer.repository + default: rancher/mirrored-longhornio-csi-resizer + description: "Repository for the CSI Resizer image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Resizer Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.resizer.tag + default: v1.13.1 + description: "Tag for the CSI Resizer image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Resizer Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.snapshotter.repository + default: rancher/mirrored-longhornio-csi-snapshotter + description: "Repository for the CSI Snapshotter image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Snapshotter Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.snapshotter.tag + default: v7.0.2-20250204 + description: "Tag for the CSI Snapshotter image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Snapshotter Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.livenessProbe.repository + default: rancher/mirrored-longhornio-livenessprobe + description: "Repository for the CSI liveness probe image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Liveness Probe Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.livenessProbe.tag + default: v2.15.0 + description: "Tag for the CSI liveness probe image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Liveness Probe Image Tag + group: "Longhorn CSI Driver Images" +- variable: privateRegistry.registryUrl + label: Private registry URL + description: "URL of a private registry. When unspecified, Longhorn uses the default system registry." + group: "Private Registry Settings" + type: string + default: "" +- variable: privateRegistry.registrySecret + label: Private registry secret name + description: "Kubernetes secret that allows you to pull images from a private registry. This setting applies only when creation of private registry secrets is enabled. You must include the private registry name in the secret name." + group: "Private Registry Settings" + type: string + default: "" +- variable: privateRegistry.createSecret + default: "true" + description: "Setting that allows you to create a private registry secret." + type: boolean + group: "Private Registry Settings" + label: Create Secret for Private Registry Settings + show_subquestion_if: true + subquestions: + - variable: privateRegistry.registryUser + label: Private registry user + description: "User account used for authenticating with a private registry." + type: string + default: "" + - variable: privateRegistry.registryPasswd + label: Private registry password + description: "Password for authenticating with a private registry." + type: password + default: "" +- variable: longhorn.default_setting + default: "false" + description: "Customize the default settings before installing Longhorn for the first time. This option will only work if the cluster hasn't installed Longhorn." + label: "Customize Default Settings" + type: boolean + show_subquestion_if: true + group: "Longhorn Default Settings" + subquestions: + - variable: csi.kubeletRootDir + default: + description: "kubelet root directory. When unspecified, Longhorn uses the default value." + type: string + label: Kubelet Root Directory + group: "Longhorn CSI Driver Settings" + - variable: csi.attacherReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Attacher. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Attacher replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.provisionerReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Provisioner. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Provisioner replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.resizerReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Resizer. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Resizer replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.snapshotterReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Snapshotter. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Snapshotter replica count + group: "Longhorn CSI Driver Settings" + - variable: defaultSettings.backupTarget + label: Backup Target + description: "Endpoint used to access the backupstore. (Options: \"NFS\", \"CIFS\", \"AWS\", \"GCP\", \"AZURE\")" + group: "Longhorn Default Settings" + type: string + default: + - variable: defaultSettings.backupTargetCredentialSecret + label: Backup Target Credential Secret + description: "Name of the Kubernetes secret associated with the backup target." + group: "Longhorn Default Settings" + type: string + default: + - variable: defaultSettings.allowRecurringJobWhileVolumeDetached + label: Allow Recurring Job While Volume Is Detached + description: 'Setting that allows Longhorn to automatically attach a volume and create snapshots or backups when recurring jobs are run.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.snapshotMaxCount + label: Snapshot Maximum Count + description: 'Maximum snapshot count for a volume. The value should be between 2 to 250.' + group: "Longhorn Default Settings" + type: int + min: 2 + max: 250 + default: 250 + - variable: defaultSettings.createDefaultDiskLabeledNodes + label: Create Default Disk on Labeled Nodes + description: 'Setting that allows Longhorn to automatically create a default disk only on nodes with the label "node.longhorn.io/create-default-disk=true" (if no other disks exist). When this setting is disabled, Longhorn creates a default disk on each node that is added to the cluster.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.defaultDataPath + label: Default Data Path + description: 'Default path for storing data on a host. The default value is "/var/lib/longhorn/".' + group: "Longhorn Default Settings" + type: string + default: "/var/lib/longhorn/" + - variable: defaultSettings.defaultDataLocality + label: Default Data Locality + description: 'Default data locality. A Longhorn volume has data locality if a local replica of the volume exists on the same node as the pod that is using the volume.' + group: "Longhorn Default Settings" + type: enum + options: + - "disabled" + - "best-effort" + default: "disabled" + - variable: defaultSettings.replicaSoftAntiAffinity + label: Replica Node Level Soft Anti-Affinity + description: 'Allow scheduling on nodes with existing healthy replicas of the same volume. By default, false.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.replicaAutoBalance + label: Replica Auto Balance + description: 'Enable this setting automatically re-balances replicas when discovered an available node.' + group: "Longhorn Default Settings" + type: enum + options: + - "disabled" + - "least-effort" + - "best-effort" + default: "disabled" + - variable: defaultSettings.storageOverProvisioningPercentage + label: Storage Over Provisioning Percentage + description: "Percentage of storage that can be allocated relative to hard drive capacity. The default value is 100." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 100 + - variable: defaultSettings.storageMinimalAvailablePercentage + label: Storage Minimal Available Percentage + description: "If the minimum available disk capacity exceeds the actual percentage of available disk capacity, the disk becomes unschedulable until more space is freed up. By default, 25." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 100 + default: 25 + - variable: defaultSettings.storageReservedPercentageForDefaultDisk + label: Storage Reserved Percentage For Default Disk + description: "The reserved percentage specifies the percentage of disk space that will not be allocated to the default disk on each new Longhorn node." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 100 + default: 30 + - variable: defaultSettings.upgradeChecker + label: Enable Upgrade Checker + description: 'Upgrade Checker that periodically checks for new Longhorn versions. When a new version is available, a notification appears on the Longhorn UI. This setting is enabled by default.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.defaultReplicaCount + label: Default Replica Count + description: "Default number of replicas for volumes created using the Longhorn UI. For Kubernetes configuration, modify the `numberOfReplicas` field in the StorageClass. The default value is \"3\"." + group: "Longhorn Default Settings" + type: int + min: 1 + max: 20 + default: 3 + - variable: defaultSettings.defaultLonghornStaticStorageClass + label: Default Longhorn Static StorageClass Name + description: "Default Longhorn StorageClass. \"storageClassName\" is assigned to PVs and PVCs that are created for an existing Longhorn volume. \"storageClassName\" can also be used as a label, so it is possible to use a Longhorn StorageClass to bind a workload to an existing PV without creating a Kubernetes StorageClass object. The default value is \"longhorn-static\"." + group: "Longhorn Default Settings" + type: string + default: "longhorn-static" + - variable: defaultSettings.backupstorePollInterval + label: Backupstore Poll Interval + description: "Number of seconds that Longhorn waits before checking the backupstore for new backups. The default value is \"300\". When the value is \"0\", polling is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 300 + - variable: defaultSettings.failedBackupTTL + label: Failed Backup Time to Live + description: "Number of minutes that Longhorn keeps a failed backup resource. When the value is \"0\", automatic deletion is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1440 + - variable: defaultSettings.backupExecutionTimeout + label: Backup Execution Timeout + description: "Number of minutes that Longhorn allows for the backup execution. The default value is \"1\"." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 1 + - variable: defaultSettings.restoreVolumeRecurringJobs + label: Restore Volume Recurring Jobs + description: "Restore recurring jobs from the backup volume on the backup target and create recurring jobs if not exist during a backup restoration." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.recurringSuccessfulJobsHistoryLimit + label: Cronjob Successful Jobs History Limit + description: "This setting specifies how many successful backup or snapshot job histories should be retained. History will not be retained if the value is 0." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.recurringFailedJobsHistoryLimit + label: Cronjob Failed Jobs History Limit + description: 'Maximum number of failed recurring backup and snapshot jobs to be retained. When the value is "0", a history of failed recurring jobs is not retained.' + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.recurringJobMaxRetention + label: Maximum Retention Number for Recurring Job + description: "Maximum number of snapshots or backups to be retained." + group: "Longhorn Default Settings" + type: int + default: 100 + - variable: defaultSettings.supportBundleFailedHistoryLimit + label: SupportBundle Failed History Limit + description: "This setting specifies how many failed support bundles can exist in the cluster. Set this value to **0** to have Longhorn automatically purge all failed support bundles." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.autoSalvage + label: Automatic salvage + description: "Setting that allows Longhorn to automatically salvage volumes when all replicas become faulty (for example, when the network connection is interrupted). Longhorn determines which replicas are usable and then uses these replicas for the volume. This setting is enabled by default." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly + label: Automatically Delete Workload Pod when The Volume Is Detached Unexpectedly + description: 'Setting that allows Longhorn to automatically delete a workload pod that is managed by a controller (for example, daemonset) whenever a Longhorn volume is detached unexpectedly (for example, during Kubernetes upgrades). After deletion, the controller restarts the pod and then Kubernetes handles volume reattachment and remounting.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.disableSchedulingOnCordonedNode + label: Disable Scheduling On Cordoned Node + description: "Setting that prevents Longhorn Manager from scheduling replicas on a cordoned Kubernetes node. This setting is enabled by default." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.replicaZoneSoftAntiAffinity + label: Replica Zone Level Soft Anti-Affinity + description: "Allow scheduling new Replicas of Volume to the Nodes in the same Zone as existing healthy Replicas. Nodes don't belong to any Zone will be treated as in the same Zone. Notice that Longhorn relies on label `topology.kubernetes.io/zone=` in the Kubernetes node object to identify the zone. By, default true." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.replicaDiskSoftAntiAffinity + label: Replica Disk Level Soft Anti-Affinity + description: 'Allow scheduling on disks with existing healthy replicas of the same volume. By default, true.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.allowEmptyNodeSelectorVolume + label: Allow Empty Node Selector Volume + description: "Setting that allows scheduling of empty node selector volumes to any node." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.allowEmptyDiskSelectorVolume + label: Allow Empty Disk Selector Volume + description: "Setting that allows scheduling of empty disk selector volumes to any disk." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.nodeDownPodDeletionPolicy + label: Pod Deletion Policy When Node is Down + description: "Policy that defines the action Longhorn takes when a volume is stuck with a StatefulSet or Deployment pod on a node that failed." + group: "Longhorn Default Settings" + type: enum + options: + - "do-nothing" + - "delete-statefulset-pod" + - "delete-deployment-pod" + - "delete-both-statefulset-and-deployment-pod" + default: "do-nothing" + - variable: defaultSettings.nodeDrainPolicy + label: Node Drain Policy + description: "Policy that defines the action Longhorn takes when a node with the last healthy replica of a volume is drained." + group: "Longhorn Default Settings" + type: enum + options: + - "block-for-eviction" + - "block-for-eviction-if-contains-last-replica" + - "block-if-contains-last-replica" + - "allow-if-replica-is-stopped" + - "always-allow" + default: "block-if-contains-last-replica" + - variable: defaultSettings.detachManuallyAttachedVolumesWhenCordoned + label: Detach Manually Attached Volumes When Cordoned + description: "Setting that allows automatic detaching of manually-attached volumes when a node is cordoned." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.priorityClass + label: Priority Class + description: "PriorityClass for system-managed Longhorn components. This setting can help prevent Longhorn components from being evicted under Node Pressure. Longhorn system contains user deployed components (E.g, Longhorn manager, Longhorn driver, Longhorn UI) and system managed components (E.g, instance manager, engine image, CSI driver, etc.) Note that this will be applied to Longhorn user-deployed components by default if there are no priority class values set yet, such as `longhornManager.priorityClass`. WARNING: DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES." + group: "Longhorn Default Settings" + type: string + default: "longhorn-critical" + - variable: defaultSettings.replicaReplenishmentWaitInterval + label: Replica Replenishment Wait Interval + description: "The interval in seconds determines how long Longhorn will at least wait to reuse the existing data on a failed replica rather than directly creating a new replica for a degraded volume." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 600 + - variable: defaultSettings.concurrentReplicaRebuildPerNodeLimit + label: Concurrent Replica Rebuild Per Node Limit + description: "Maximum number of replicas that can be concurrently rebuilt on each node. + WARNING: + - The old setting \"Disable Replica Rebuild\" is replaced by this setting. + - Different from relying on replica starting delay to limit the concurrent rebuilding, if the rebuilding is disabled, replica object replenishment will be directly skipped. + - When the value is 0, the eviction and data locality feature won't work. But this shouldn't have any impact to any current replica rebuild and backup restore." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 5 + - variable: defaultSettings.concurrentVolumeBackupRestorePerNodeLimit + label: Concurrent Volume Backup Restore Per Node Limit + description: "Maximum number of volumes that can be concurrently restored on each node using a backup. When the value is \"0\", restoration of volumes using a backup is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 5 + - variable: defaultSettings.disableRevisionCounter + label: Disable Revision Counter + description: "Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the \"volume-head-xxx.img\" file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. This setting applies only to volumes created using the Longhorn UI." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.systemManagedPodsImagePullPolicy + label: System Managed Pod Image Pull Policy + description: "Image pull policy for system-managed pods, such as Instance Manager, engine images, and CSI Driver. Changes to the image pull policy are applied only after the system-managed pods restart." + group: "Longhorn Default Settings" + type: enum + options: + - "if-not-present" + - "always" + - "never" + default: "if-not-present" + - variable: defaultSettings.allowVolumeCreationWithDegradedAvailability + label: Allow Volume Creation with Degraded Availability + description: "Setting that allows you to create and attach a volume without having all replicas scheduled at the time of creation." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoCleanupSystemGeneratedSnapshot + label: Automatically Cleanup System Generated Snapshot + description: "Setting that allows Longhorn to automatically clean up the system-generated snapshot after replica rebuilding is completed." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoCleanupRecurringJobBackupSnapshot + label: Automatically Cleanup Recurring Job Backup Snapshot + description: "Setting that allows Longhorn to automatically clean up the snapshot generated by a recurring backup job." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit + label: Concurrent Automatic Engine Upgrade Per Node Limit + description: "Maximum number of engines that are allowed to concurrently upgrade on each node after Longhorn Manager is upgraded. When the value is \"0\", Longhorn does not automatically upgrade volume engines to the new default engine image version." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 0 + - variable: defaultSettings.backingImageCleanupWaitInterval + label: Backing Image Cleanup Wait Interval + description: "Number of minutes that Longhorn waits before cleaning up the backing image file when no replicas in the disk are using it." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 60 + - variable: defaultSettings.backingImageRecoveryWaitInterval + label: Backing Image Recovery Wait Interval + description: "Number of seconds that Longhorn waits before downloading a backing image file again when the status of all image disk files changes to \"failed\" or \"unknown\"." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 300 + - variable: defaultSettings.guaranteedInstanceManagerCPU + label: Guaranteed Instance Manager CPU + description: "Percentage of the total allocatable CPU resources on each node to be reserved for each instance manager pod when the V1 Data Engine is enabled. The default value is \"12\". + WARNING: + - Value 0 means removing the CPU requests from spec of instance manager pods. + - Considering the possible number of new instance manager pods in a further system upgrade, this integer value ranges from 0 to 40. + - One more set of instance manager pods may need to be deployed when the Longhorn system is upgraded. If current available CPUs of the nodes are not enough for the new instance manager pods, you need to detach the volumes using the oldest instance manager pods so that Longhorn can clean up the old pods automatically and release the CPU resources. And the new pods with the latest instance manager image will be launched then. + - This global setting will be ignored for a node if the field \"InstanceManagerCPURequest\" on the node is set. + - After this setting is changed, all instance manager pods using this global setting on all the nodes will be automatically restarted. In other words, DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 40 + default: 12 + - variable: defaultSettings.logLevel + label: Log Level + description: 'Log levels that indicate the type and severity of logs in Longhorn Manager. The default value is "Info". (Options: "Panic", "Fatal", "Error", "Warn", "Info", "Debug", "Trace")' + group: "Longhorn Default Settings" + type: string + default: "Info" + - variable: defaultSettings.disableSnapshotPurge + label: Disable Snapshot Purge + description: "Setting that temporarily prevents all attempts to purge volume snapshots." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.freezeFilesystemForSnapshot + description: "Setting that freezes the filesystem on the root partition before a snapshot is created." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.kubernetesClusterAutoscalerEnabled + label: Kubernetes Cluster Autoscaler Enabled (Experimental) + description: "Setting that notifies Longhorn that the cluster is using the Kubernetes Cluster Autoscaler. + WARNING: + - Replica rebuilding could be expensive because nodes with reusable replicas could get removed by the Kubernetes Cluster Autoscaler." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.orphanAutoDeletion + label: Orphaned Data Cleanup + description: "Setting that allows Longhorn to automatically delete an orphaned resource and the corresponding data (for example, stale replicas). Orphaned resources on failed or unknown nodes are not automatically cleaned up." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.storageNetwork + label: Storage Network + description: "Longhorn uses the storage network for in-cluster data traffic. Leave this blank to use the Kubernetes cluster network. + WARNING: + - This setting should change after detaching all Longhorn volumes, as some of the Longhorn system component pods will get recreated to apply the setting. Longhorn will try to block this setting update when there are attached volumes." + group: "Longhorn Default Settings" + type: string + default: +- variable: defaultSettings.deletingConfirmationFlag + label: Deleting Confirmation Flag + description: "Flag that prevents accidental uninstallation of Longhorn." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.engineReplicaTimeout + label: Timeout between Engine and Replica + description: "Timeout between the Longhorn Engine and replicas. Specify a value between \"8\" and \"30\" seconds. The default value is \"8\"." + group: "Longhorn Default Settings" + type: int + default: "8" +- variable: defaultSettings.snapshotDataIntegrity + label: Snapshot Data Integrity + description: "This setting allows users to enable or disable snapshot hashing and data integrity checking." + group: "Longhorn Default Settings" + type: string + default: "disabled" +- variable: defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation + label: Immediate Snapshot Data Integrity Check After Creating a Snapshot + description: "Hashing snapshot disk files impacts the performance of the system. The immediate snapshot hashing and checking can be disabled to minimize the impact after creating a snapshot." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.snapshotDataIntegrityCronjob + label: Snapshot Data Integrity Check CronJob + description: "Unix-cron string format. The setting specifies when Longhorn checks the data integrity of snapshot disk files." + group: "Longhorn Default Settings" + type: string + default: "0 0 */7 * *" +- variable: defaultSettings.removeSnapshotsDuringFilesystemTrim + label: Remove Snapshots During Filesystem Trim + description: "This setting allows Longhorn filesystem trim feature to automatically mark the latest snapshot and its ancestors as removed and stops at the snapshot containing multiple children." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.fastReplicaRebuildEnabled + label: Fast Replica Rebuild Enabled + description: "Setting that allows fast rebuilding of replicas using the checksum of snapshot disk files. Before enabling this setting, you must set the snapshot-data-integrity value to \"enable\" or \"fast-check\"." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.replicaFileSyncHttpClientTimeout + label: Timeout of HTTP Client to Replica File Sync Server + description: "In seconds. The setting specifies the HTTP client timeout to the file sync server." + group: "Longhorn Default Settings" + type: int + default: "30" +- variable: defaultSettings.longGRPCTimeOut + label: Long gRPC Timeout + description: "Number of seconds that Longhorn allows for the completion of replica rebuilding and snapshot cloning operations." + group: "Longhorn Default Settings" + type: int + default: "86400" +- variable: defaultSettings.backupCompressionMethod + label: Backup Compression Method + description: "Setting that allows you to specify a backup compression method." + group: "Longhorn Default Settings" + type: string + default: "lz4" +- variable: defaultSettings.backupConcurrentLimit + label: Backup Concurrent Limit Per Backup + description: "Maximum number of worker threads that can concurrently run for each backup." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 2 +- variable: defaultSettings.restoreConcurrentLimit + label: Restore Concurrent Limit Per Backup + description: "This setting controls how many worker threads per restore concurrently." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 2 +- variable: defaultSettings.allowCollectingLonghornUsageMetrics + label: Allow Collecting Longhorn Usage Metrics + description: "Setting that allows Longhorn to periodically collect anonymous usage data for product improvement purposes. Longhorn sends collected data to the [Upgrade Responder](https://github.com/longhorn/upgrade-responder) server, which is the data source of the Longhorn Public Metrics Dashboard (https://metrics.longhorn.io). The Upgrade Responder server does not store data that can be used to identify clients, including IP addresses." + group: "Longhorn Default Settings" + type: boolean + default: true +- variable: defaultSettings.v1DataEngine + label: V1 Data Engine + description: "Setting that allows you to enable the V1 Data Engine." + group: "Longhorn V1 Data Engine Settings" + type: boolean + default: true +- variable: defaultSettings.v2DataEngine + label: V2 Data Engine + description: "Setting that allows you to enable the V2 Data Engine, which is based on the Storage Performance Development Kit (SPDK). The V2 Data Engine is a preview feature and should not be used in production environments. + WARNING: + - DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES. Longhorn will block this setting update when there are attached volumes. + - When the V2 Data Engine is enabled, each instance-manager pod utilizes 1 CPU core. This high CPU usage is attributed to the spdk_tgt process running within each instance-manager pod. The spdk_tgt process is responsible for handling input/output (IO) operations and requires intensive polling. As a result, it consumes 100% of a dedicated CPU core to efficiently manage and process the IO requests, ensuring optimal performance and responsiveness for storage operations." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: boolean + default: false +- variable: defaultSettings.v2DataEngineHugepageLimit + label: V2 Data Engine + description: "This allows users to configure maximum huge page size (in MiB) for the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: int + default: "2048" +- variable: defaultSettings.v2DataEngineLogLevel + label: V2 Data Engine + description: "Setting that allows you to configure the log level of the SPDK target daemon (spdk_tgt) of the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: enum + options: + - "Disabled" + - "Error" + - "Warn" + - "Notice" + - "Info" + - "Debug" + default: "Notice" +- variable: defaultSettings.v2DataEngineLogFlags + label: V2 Data Engine + description: "Setting that allows you to configure the log flags of the SPDK target daemon (spdk_tgt) of the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: string + default: +- variable: defaultSettings.autoCleanupSnapshotWhenDeleteBackup + label: Auto Cleanup Snapshot When Delete Backup + description: "Setting that automatically cleans up the snapshot when the backup is deleted." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.rwxVolumeFastFailover + label: RWX Volume Fast Failover (Experimental) + description: "Turn on logic to detect and move RWX volumes quickly on node failure." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: persistence.defaultClass + default: "true" + description: "Setting that allows you to specify the default Longhorn StorageClass." + label: Default Storage Class + group: "Longhorn Storage Class Settings" + required: true + type: boolean +- variable: persistence.reclaimPolicy + label: Storage Class Retain Policy + description: "Reclaim policy that provides instructions for handling of a volume after its claim is released. (Options: \"Retain\", \"Delete\")" + group: "Longhorn Storage Class Settings" + required: true + type: enum + options: + - "Delete" + - "Retain" + default: "Delete" +- variable: persistence.disableRevisionCounter + label: Default Storage Class Disable Revision Counter + description: "Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the volume-head-xxx.img file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. (Options: \"true\", \"false\")" + group: "Longhorn Storage Class Settings" + required: true + type: enum + options: + - "true" + - "false" + default: "true" +- variable: persistence.defaultClassReplicaCount + description: "Replica count of the default Longhorn StorageClass." + label: Default Storage Class Replica Count + group: "Longhorn Storage Class Settings" + type: int + min: 1 + max: 10 + default: 3 +- variable: persistence.defaultDataLocality + description: "Data locality of the default Longhorn StorageClass. (Options: \"disabled\", \"best-effort\")" + label: Default Storage Class Data Locality + group: "Longhorn Storage Class Settings" + type: enum + options: + - "disabled" + - "best-effort" + default: "disabled" +- variable: persistence.recurringJobSelector.enable + description: "Setting that allows you to enable the recurring job selector for a Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Recurring Job Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.recurringJobSelector.jobList + description: 'Recurring job selector for a Longhorn StorageClass. Ensure that quotes are used correctly when specifying job parameters. (Example: `[{"name":"backup", "isGroup":true}]`)' + label: Storage Class Recurring Job Selector List + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.defaultDiskSelector.enable + description: "Setting that allows you to enable the disk selector for the default Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Disk Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.defaultDiskSelector.selector + label: Storage Class Disk Selector + description: 'Disk selector for the default Longhorn StorageClass. Longhorn uses only disks with the specified tags for storing volume data. (Examples: "nvme,sata")' + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.defaultNodeSelector.enable + description: "Setting that allows you to enable the node selector for the default Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Node Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.defaultNodeSelector.selector + label: Storage Class Node Selector + description: 'Node selector for the default Longhorn StorageClass. Longhorn uses only nodes with the specified tags for storing volume data. (Examples: "storage,fast")' + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.backingImage.enable + description: "Setting that allows you to use a backing image in a Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Default Storage Class Backing Image + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.backingImage.name + description: 'Backing image to be used for creating and restoring volumes in a Longhorn StorageClass. When no backing images are available, specify the data source type and parameters that Longhorn can use to create a backing image.' + label: Storage Class Backing Image Name + group: "Longhorn Storage Class Settings" + type: string + default: + - variable: persistence.backingImage.expectedChecksum + description: 'Expected SHA-512 checksum of a backing image used in a Longhorn StorageClass. + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - It is not recommended to set this field if the data source type is \"export-from-volume\".' + label: Storage Class Backing Image Expected SHA512 Checksum + group: "Longhorn Storage Class Settings" + type: string + default: + - variable: persistence.backingImage.dataSourceType + description: 'Data source type of a backing image used in a Longhorn StorageClass. If the backing image exists in the cluster, Longhorn uses this setting to verify the image. If the backing image does not exist, Longhorn creates one using the specified data source type. + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - As for backing image creation with data source type \"upload\", it is recommended to do it via UI rather than StorageClass here. Uploading requires file data sending to the Longhorn backend after the object creation, which is complicated if you want to handle it manually.' + label: Storage Class Backing Image Data Source Type + group: "Longhorn Storage Class Settings" + type: enum + options: + - "" + - "download" + - "upload" + - "export-from-volume" + default: "" + - variable: persistence.backingImage.dataSourceParameters + description: "Data source parameters of a backing image used in a Longhorn StorageClass. You can specify a JSON string of a map. (Example: `'{\"url\":\"https://backing-image-example.s3-region.amazonaws.com/test-backing-image\"}'`) + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - Be careful of the quotes here." + label: Storage Class Backing Image Data Source Parameters + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.removeSnapshotsDuringFilesystemTrim + description: "Setting that allows you to enable automatic snapshot removal during filesystem trim for a Longhorn StorageClass. (Options: \"ignored\", \"enabled\", \"disabled\")" + label: Default Storage Class Remove Snapshots During Filesystem Trim + group: "Longhorn Storage Class Settings" + type: enum + options: + - "ignored" + - "enabled" + - "disabled" + default: "ignored" +- variable: ingress.enabled + default: "false" + description: "Expose app using Layer 7 Load Balancer - ingress" + type: boolean + group: "Services and Load Balancing" + label: Expose app using Layer 7 Load Balancer + show_subquestion_if: true + subquestions: + - variable: ingress.host + default: "xip.io" + description: "Hostname of the Layer 7 load balancer." + type: hostname + required: true + label: Layer 7 Load Balancer Hostname + - variable: ingress.path + default: "/" + description: "Default ingress path. You can access the Longhorn UI by following the full ingress path {{host}}+{{path}}." + type: string + required: true + label: Ingress Path + - variable: ingress.pathType + default: "ImplementationSpecific" + description: "Path type for the ingress. (Options: \"ImplementationSpecific\", \"Exact\", \"Prefix\")" + type: enum + options: + - "ImplementationSpecific" + - "Exact" + - "Prefix" + required: true + label: Ingress Path Type +- variable: service.ui.type + default: "Rancher-Proxy" + description: "Service type for Longhorn UI. (Options: \"ClusterIP\", \"NodePort\", \"LoadBalancer\", \"Rancher-Proxy\")" + type: enum + options: + - "ClusterIP" + - "NodePort" + - "LoadBalancer" + - "Rancher-Proxy" + label: Longhorn UI Service + show_if: "ingress.enabled=false" + group: "Services and Load Balancing" + show_subquestion_if: "NodePort" + subquestions: + - variable: service.ui.nodePort + default: "" + description: "NodePort port number for Longhorn UI. When unspecified, Longhorn selects a free port between 30000 and 32767." + type: int + min: 30000 + max: 32767 + show_if: "service.ui.type=NodePort||service.ui.type=LoadBalancer" + label: UI Service NodePort number +- variable: enablePSP + default: "false" + description: "Setting that allows you to enable pod security policies (PSPs) that allow privileged Longhorn pods to start. This setting applies only to clusters running Kubernetes 1.25 and earlier, and with the built-in Pod Security admission controller enabled." + label: Pod Security Policy + type: boolean + group: "Other Settings" +- variable: global.cattle.windowsCluster.enabled + default: "false" + description: "Setting that allows Longhorn to run on a Rancher Windows cluster." + label: Rancher Windows Cluster + type: boolean + group: "Other Settings" +- variable: networkPolicies.enabled + description: "Setting that allows you to enable network policies that control access to Longhorn pods. + Warning: The Rancher Proxy will not work if this feature is enabled and a custom NetworkPolicy must be added." + group: "Other Settings" + label: Network Policies + default: "false" + type: boolean + subquestions: + - variable: networkPolicies.type + label: Network Policies for Ingress + description: "Distribution that determines the policy for allowing access for an ingress. (Options: \"k3s\", \"rke2\", \"rke1\")" + show_if: "networkPolicies.enabled=true&&ingress.enabled=true" + type: enum + default: "rke2" + options: + - "rke1" + - "rke2" + - "k3s" + - variable: defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU + label: Guaranteed Instance Manager CPU for V2 Data Engine + description: 'Number of millicpus on each node to be reserved for each Instance Manager pod when the V2 Data Engine is enabled. The default value is "1250". + WARNING: + - Specifying a value of 0 disables CPU requests for instance manager pods. You must specify an integer between 1000 and 8000. + - This is a global setting. Modifying the value triggers an automatic restart of the instance manager pods. Do not modify the value while volumes are still attached." + group: "Longhorn Default Settings' + type: int + min: 1000 + max: 8000 + default: 1250 diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/NOTES.txt b/charts/longhorn/105.1.1+up1.7.3/templates/NOTES.txt new file mode 100644 index 0000000000..cca7cd77b9 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/NOTES.txt @@ -0,0 +1,5 @@ +Longhorn is now installed on the cluster! + +Please wait a few minutes for other Longhorn components such as CSI deployments, Engine Images, and Instance Managers to be initialized. + +Visit our documentation at https://longhorn.io/docs/ diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/_helpers.tpl b/charts/longhorn/105.1.1+up1.7.3/templates/_helpers.tpl new file mode 100644 index 0000000000..3fbc2ac02f --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/_helpers.tpl @@ -0,0 +1,66 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "longhorn.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +*/}} +{{- define "longhorn.fullname" -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "longhorn.managerIP" -}} +{{- $fullname := (include "longhorn.fullname" .) -}} +{{- printf "http://%s-backend:9500" $fullname | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "secret" }} +{{- printf "{\"auths\": {\"%s\": {\"auth\": \"%s\"}}}" .Values.privateRegistry.registryUrl (printf "%s:%s" .Values.privateRegistry.registryUser .Values.privateRegistry.registryPasswd | b64enc) | b64enc }} +{{- end }} + +{{- /* +longhorn.labels generates the standard Helm labels. +*/ -}} +{{- define "longhorn.labels" -}} +app.kubernetes.io/name: {{ template "longhorn.name" . }} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +app.kubernetes.io/instance: {{ .Release.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +{{- end -}} + + +{{- define "system_default_registry" -}} +{{- if .Values.global.cattle.systemDefaultRegistry -}} +{{- printf "%s/" .Values.global.cattle.systemDefaultRegistry -}} +{{- else -}} +{{- "" -}} +{{- end -}} +{{- end -}} + +{{- define "registry_url" -}} +{{- if .Values.privateRegistry.registryUrl -}} +{{- printf "%s/" .Values.privateRegistry.registryUrl -}} +{{- else -}} +{{ include "system_default_registry" . }} +{{- end -}} +{{- end -}} + +{{- /* + define the longhorn release namespace +*/ -}} +{{- define "release_namespace" -}} +{{- if .Values.namespaceOverride -}} +{{- .Values.namespaceOverride -}} +{{- else -}} +{{- .Release.Namespace -}} +{{- end -}} +{{- end -}} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/clusterrole.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/clusterrole.yaml new file mode 100644 index 0000000000..c065f1726c --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/clusterrole.yaml @@ -0,0 +1,77 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: longhorn-role + labels: {{- include "longhorn.labels" . | nindent 4 }} +rules: +- apiGroups: + - apiextensions.k8s.io + resources: + - customresourcedefinitions + verbs: + - "*" +- apiGroups: [""] + resources: ["pods", "events", "persistentvolumes", "persistentvolumeclaims","persistentvolumeclaims/status", "nodes", "proxy/nodes", "pods/log", "secrets", "services", "endpoints", "configmaps", "serviceaccounts"] + verbs: ["*"] +- apiGroups: [""] + resources: ["namespaces"] + verbs: ["get", "list"] +- apiGroups: ["apps"] + resources: ["daemonsets", "statefulsets", "deployments"] + verbs: ["*"] +- apiGroups: ["batch"] + resources: ["jobs", "cronjobs"] + verbs: ["*"] +- apiGroups: ["policy"] + resources: ["poddisruptionbudgets", "podsecuritypolicies"] + verbs: ["*"] +- apiGroups: ["scheduling.k8s.io"] + resources: ["priorityclasses"] + verbs: ["watch", "list"] +- apiGroups: ["storage.k8s.io"] + resources: ["storageclasses", "volumeattachments", "volumeattachments/status", "csinodes", "csidrivers"] + verbs: ["*"] +- apiGroups: ["snapshot.storage.k8s.io"] + resources: ["volumesnapshotclasses", "volumesnapshots", "volumesnapshotcontents", "volumesnapshotcontents/status"] + verbs: ["*"] +- apiGroups: ["longhorn.io"] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", "settings/status", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + {{- if .Values.openshift.enabled }} + "engineimages/finalizers", "nodes/finalizers", "instancemanagers/finalizers", + {{- end }} + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status", "backupbackingimages", "backupbackingimages/status"] + verbs: ["*"] +- apiGroups: ["coordination.k8s.io"] + resources: ["leases"] + verbs: ["*"] +- apiGroups: ["metrics.k8s.io"] + resources: ["pods", "nodes"] + verbs: ["get", "list"] +- apiGroups: ["apiregistration.k8s.io"] + resources: ["apiservices"] + verbs: ["list", "watch"] +- apiGroups: ["admissionregistration.k8s.io"] + resources: ["mutatingwebhookconfigurations", "validatingwebhookconfigurations"] + verbs: ["get", "list", "create", "patch", "delete"] +- apiGroups: ["rbac.authorization.k8s.io"] + resources: ["roles", "rolebindings", "clusterrolebindings", "clusterroles"] + verbs: ["*"] +{{- if .Values.openshift.enabled }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: longhorn-ocp-privileged-role + labels: {{- include "longhorn.labels" . | nindent 4 }} +rules: +- apiGroups: ["security.openshift.io"] + resources: ["securitycontextconstraints"] + resourceNames: ["anyuid", "privileged"] + verbs: ["use"] +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/clusterrolebinding.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/clusterrolebinding.yaml new file mode 100644 index 0000000000..2e34f014ce --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/clusterrolebinding.yaml @@ -0,0 +1,49 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-bind + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: longhorn-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-support-bundle + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: +- kind: ServiceAccount + name: longhorn-support-bundle + namespace: {{ include "release_namespace" . }} +{{- if .Values.openshift.enabled }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-ocp-privileged-bind + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: longhorn-ocp-privileged-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: longhorn-ui-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: default # supportbundle-agent-support-bundle uses default sa + namespace: {{ include "release_namespace" . }} +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/daemonset-sa.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/daemonset-sa.yaml new file mode 100644 index 0000000000..0bba12034a --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/daemonset-sa.yaml @@ -0,0 +1,188 @@ +apiVersion: apps/v1 +kind: DaemonSet +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-manager + name: longhorn-manager + namespace: {{ include "release_namespace" . }} +spec: + selector: + matchLabels: + app: longhorn-manager + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-manager + {{- with .Values.annotations }} + annotations: + {{- toYaml . | nindent 8 }} + {{- end }} + spec: + containers: + - name: longhorn-manager + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + privileged: true + command: + - longhorn-manager + - -d + {{- if eq .Values.longhornManager.log.format "json" }} + - -j + {{- end }} + - daemon + - --engine-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.engine.repository }}:{{ .Values.image.longhorn.engine.tag }}" + - --instance-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.instanceManager.repository }}:{{ .Values.image.longhorn.instanceManager.tag }}" + - --share-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.shareManager.repository }}:{{ .Values.image.longhorn.shareManager.tag }}" + - --backing-image-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.backingImageManager.repository }}:{{ .Values.image.longhorn.backingImageManager.tag }}" + - --support-bundle-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.supportBundleKit.repository }}:{{ .Values.image.longhorn.supportBundleKit.tag }}" + - --manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }}" + - --service-account + - longhorn-service-account + {{- if .Values.preUpgradeChecker.upgradeVersionCheck}} + - --upgrade-version-check + {{- end }} + ports: + - containerPort: 9500 + name: manager + - containerPort: 9501 + name: conversion-wh + - containerPort: 9502 + name: admission-wh + - containerPort: 9503 + name: recov-backend + readinessProbe: + httpGet: + path: /v1/healthz + port: 9501 + scheme: HTTPS + volumeMounts: + - name: boot + mountPath: /host/boot/ + readOnly: true + - name: dev + mountPath: /host/dev/ + - name: proc + mountPath: /host/proc/ + readOnly: true + - name: etc + mountPath: /host/etc/ + readOnly: true + - name: longhorn + mountPath: /var/lib/longhorn/ + mountPropagation: Bidirectional + - name: longhorn-grpc-tls + mountPath: /tls-files/ + {{- if .Values.enableGoCoverDir }} + - name: go-cover-dir + mountPath: /go-cover-dir/ + {{- end }} + env: + - name: POD_NAME + valueFrom: + fieldRef: + fieldPath: metadata.name + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: POD_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + {{- if .Values.enableGoCoverDir }} + - name: GOCOVERDIR + value: /go-cover-dir/ + {{- end }} + - name: pre-pull-share-manager-image + imagePullPolicy: {{ .Values.image.pullPolicy }} + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.shareManager.repository }}:{{ .Values.image.longhorn.shareManager.tag }} + command: ["sh", "-c", "echo share-manager image pulled && sleep infinity"] + volumes: + - name: boot + hostPath: + path: /boot/ + - name: dev + hostPath: + path: /dev/ + - name: proc + hostPath: + path: /proc/ + - name: etc + hostPath: + path: /etc/ + - name: longhorn + hostPath: + path: /var/lib/longhorn/ + {{- if .Values.enableGoCoverDir }} + - name: go-cover-dir + hostPath: + path: /go-cover-dir/ + type: DirectoryOrCreate + {{- end }} + - name: longhorn-grpc-tls + secret: + secretName: longhorn-grpc-tls + optional: true + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} + serviceAccountName: longhorn-service-account + updateStrategy: + rollingUpdate: + maxUnavailable: "100%" +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-manager + name: longhorn-backend + namespace: {{ include "release_namespace" . }} + {{- if .Values.longhornManager.serviceAnnotations }} + annotations: +{{ toYaml .Values.longhornManager.serviceAnnotations | indent 4 }} + {{- end }} +spec: + type: {{ .Values.service.manager.type }} + selector: + app: longhorn-manager + ports: + - name: manager + port: 9500 + targetPort: manager + {{- if .Values.service.manager.nodePort }} + nodePort: {{ .Values.service.manager.nodePort }} + {{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/default-setting.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/default-setting.yaml new file mode 100644 index 0000000000..72463f1fb2 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/default-setting.yaml @@ -0,0 +1,247 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-default-setting + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +data: + default-setting.yaml: |- + {{- if not (kindIs "invalid" .Values.defaultSettings.backupTarget) }} + backup-target: {{ .Values.defaultSettings.backupTarget }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupTargetCredentialSecret) }} + backup-target-credential-secret: {{ .Values.defaultSettings.backupTargetCredentialSecret }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowRecurringJobWhileVolumeDetached) }} + allow-recurring-job-while-volume-detached: {{ .Values.defaultSettings.allowRecurringJobWhileVolumeDetached }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.createDefaultDiskLabeledNodes) }} + create-default-disk-labeled-nodes: {{ .Values.defaultSettings.createDefaultDiskLabeledNodes }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultDataPath) }} + default-data-path: {{ .Values.defaultSettings.defaultDataPath }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaSoftAntiAffinity) }} + replica-soft-anti-affinity: {{ .Values.defaultSettings.replicaSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaAutoBalance) }} + replica-auto-balance: {{ .Values.defaultSettings.replicaAutoBalance }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageOverProvisioningPercentage) }} + storage-over-provisioning-percentage: {{ .Values.defaultSettings.storageOverProvisioningPercentage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageMinimalAvailablePercentage) }} + storage-minimal-available-percentage: {{ .Values.defaultSettings.storageMinimalAvailablePercentage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageReservedPercentageForDefaultDisk) }} + storage-reserved-percentage-for-default-disk: {{ .Values.defaultSettings.storageReservedPercentageForDefaultDisk }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.upgradeChecker) }} + upgrade-checker: {{ .Values.defaultSettings.upgradeChecker }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultReplicaCount) }} + default-replica-count: {{ .Values.defaultSettings.defaultReplicaCount }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultDataLocality) }} + default-data-locality: {{ .Values.defaultSettings.defaultDataLocality }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultLonghornStaticStorageClass) }} + default-longhorn-static-storage-class: {{ .Values.defaultSettings.defaultLonghornStaticStorageClass }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupstorePollInterval) }} + backupstore-poll-interval: {{ .Values.defaultSettings.backupstorePollInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.failedBackupTTL) }} + failed-backup-ttl: {{ .Values.defaultSettings.failedBackupTTL }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupExecutionTimeout) }} + backup-execution-timeout: {{ .Values.defaultSettings.backupExecutionTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.restoreVolumeRecurringJobs) }} + restore-volume-recurring-jobs: {{ .Values.defaultSettings.restoreVolumeRecurringJobs }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringSuccessfulJobsHistoryLimit) }} + recurring-successful-jobs-history-limit: {{ .Values.defaultSettings.recurringSuccessfulJobsHistoryLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringJobMaxRetention) }} + recurring-job-max-retention: {{ .Values.defaultSettings.recurringJobMaxRetention }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringFailedJobsHistoryLimit) }} + recurring-failed-jobs-history-limit: {{ .Values.defaultSettings.recurringFailedJobsHistoryLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.supportBundleFailedHistoryLimit) }} + support-bundle-failed-history-limit: {{ .Values.defaultSettings.supportBundleFailedHistoryLimit }} + {{- end }} + {{- if or (not (kindIs "invalid" .Values.defaultSettings.taintToleration)) (.Values.global.cattle.windowsCluster.enabled) }} + taint-toleration: {{ $windowsDefaultSettingTaintToleration := list }}{{ $defaultSettingTaintToleration := list -}} + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.defaultSetting.taintToleration -}} + {{- $windowsDefaultSettingTaintToleration = .Values.global.cattle.windowsCluster.defaultSetting.taintToleration -}} + {{- end -}} + {{- if not (kindIs "invalid" .Values.defaultSettings.taintToleration) -}} + {{- $defaultSettingTaintToleration = .Values.defaultSettings.taintToleration -}} + {{- end -}} + {{- $taintToleration := list $windowsDefaultSettingTaintToleration $defaultSettingTaintToleration }}{{ join ";" (compact $taintToleration) -}} + {{- end }} + {{- if or (not (kindIs "invalid" .Values.defaultSettings.systemManagedComponentsNodeSelector)) (.Values.global.cattle.windowsCluster.enabled) }} + system-managed-components-node-selector: {{ $windowsDefaultSettingNodeSelector := list }}{{ $defaultSettingNodeSelector := list -}} + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.defaultSetting.systemManagedComponentsNodeSelector -}} + {{ $windowsDefaultSettingNodeSelector = .Values.global.cattle.windowsCluster.defaultSetting.systemManagedComponentsNodeSelector -}} + {{- end -}} + {{- if not (kindIs "invalid" .Values.defaultSettings.systemManagedComponentsNodeSelector) -}} + {{- $defaultSettingNodeSelector = .Values.defaultSettings.systemManagedComponentsNodeSelector -}} + {{- end -}} + {{- $nodeSelector := list $windowsDefaultSettingNodeSelector $defaultSettingNodeSelector }}{{ join ";" (compact $nodeSelector) -}} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.priorityClass) }} + priority-class: {{ .Values.defaultSettings.priorityClass }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoSalvage) }} + auto-salvage: {{ .Values.defaultSettings.autoSalvage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly) }} + auto-delete-pod-when-volume-detached-unexpectedly: {{ .Values.defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableSchedulingOnCordonedNode) }} + disable-scheduling-on-cordoned-node: {{ .Values.defaultSettings.disableSchedulingOnCordonedNode }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaZoneSoftAntiAffinity) }} + replica-zone-soft-anti-affinity: {{ .Values.defaultSettings.replicaZoneSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaDiskSoftAntiAffinity) }} + replica-disk-soft-anti-affinity: {{ .Values.defaultSettings.replicaDiskSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.nodeDownPodDeletionPolicy) }} + node-down-pod-deletion-policy: {{ .Values.defaultSettings.nodeDownPodDeletionPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.nodeDrainPolicy) }} + node-drain-policy: {{ .Values.defaultSettings.nodeDrainPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.detachManuallyAttachedVolumesWhenCordoned) }} + detach-manually-attached-volumes-when-cordoned: {{ .Values.defaultSettings.detachManuallyAttachedVolumesWhenCordoned }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaReplenishmentWaitInterval) }} + replica-replenishment-wait-interval: {{ .Values.defaultSettings.replicaReplenishmentWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentReplicaRebuildPerNodeLimit) }} + concurrent-replica-rebuild-per-node-limit: {{ .Values.defaultSettings.concurrentReplicaRebuildPerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentVolumeBackupRestorePerNodeLimit) }} + concurrent-volume-backup-restore-per-node-limit: {{ .Values.defaultSettings.concurrentVolumeBackupRestorePerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableRevisionCounter) }} + disable-revision-counter: {{ .Values.defaultSettings.disableRevisionCounter }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.systemManagedPodsImagePullPolicy) }} + system-managed-pods-image-pull-policy: {{ .Values.defaultSettings.systemManagedPodsImagePullPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowVolumeCreationWithDegradedAvailability) }} + allow-volume-creation-with-degraded-availability: {{ .Values.defaultSettings.allowVolumeCreationWithDegradedAvailability }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupSystemGeneratedSnapshot) }} + auto-cleanup-system-generated-snapshot: {{ .Values.defaultSettings.autoCleanupSystemGeneratedSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupRecurringJobBackupSnapshot) }} + auto-cleanup-recurring-job-backup-snapshot: {{ .Values.defaultSettings.autoCleanupRecurringJobBackupSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit) }} + concurrent-automatic-engine-upgrade-per-node-limit: {{ .Values.defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backingImageCleanupWaitInterval) }} + backing-image-cleanup-wait-interval: {{ .Values.defaultSettings.backingImageCleanupWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backingImageRecoveryWaitInterval) }} + backing-image-recovery-wait-interval: {{ .Values.defaultSettings.backingImageRecoveryWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.guaranteedInstanceManagerCPU) }} + guaranteed-instance-manager-cpu: {{ .Values.defaultSettings.guaranteedInstanceManagerCPU }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.kubernetesClusterAutoscalerEnabled) }} + kubernetes-cluster-autoscaler-enabled: {{ .Values.defaultSettings.kubernetesClusterAutoscalerEnabled }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.orphanAutoDeletion) }} + orphan-auto-deletion: {{ .Values.defaultSettings.orphanAutoDeletion }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageNetwork) }} + storage-network: {{ .Values.defaultSettings.storageNetwork }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.deletingConfirmationFlag) }} + deleting-confirmation-flag: {{ .Values.defaultSettings.deletingConfirmationFlag }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.engineReplicaTimeout) }} + engine-replica-timeout: {{ .Values.defaultSettings.engineReplicaTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrity) }} + snapshot-data-integrity: {{ .Values.defaultSettings.snapshotDataIntegrity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation) }} + snapshot-data-integrity-immediate-check-after-snapshot-creation: {{ .Values.defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrityCronjob) }} + snapshot-data-integrity-cronjob: {{ .Values.defaultSettings.snapshotDataIntegrityCronjob }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.removeSnapshotsDuringFilesystemTrim) }} + remove-snapshots-during-filesystem-trim: {{ .Values.defaultSettings.removeSnapshotsDuringFilesystemTrim }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.fastReplicaRebuildEnabled) }} + fast-replica-rebuild-enabled: {{ .Values.defaultSettings.fastReplicaRebuildEnabled }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaFileSyncHttpClientTimeout) }} + replica-file-sync-http-client-timeout: {{ .Values.defaultSettings.replicaFileSyncHttpClientTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.longGRPCTimeOut) }} + long-grpc-timeout: {{ .Values.defaultSettings.longGRPCTimeOut }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.logLevel) }} + log-level: {{ .Values.defaultSettings.logLevel }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupCompressionMethod) }} + backup-compression-method: {{ .Values.defaultSettings.backupCompressionMethod }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupConcurrentLimit) }} + backup-concurrent-limit: {{ .Values.defaultSettings.backupConcurrentLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.restoreConcurrentLimit) }} + restore-concurrent-limit: {{ .Values.defaultSettings.restoreConcurrentLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v1DataEngine) }} + v1-data-engine: {{ .Values.defaultSettings.v1DataEngine }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngine) }} + v2-data-engine: {{ .Values.defaultSettings.v2DataEngine }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineHugepageLimit) }} + v2-data-engine-hugepage-limit: {{ .Values.defaultSettings.v2DataEngineHugepageLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowEmptyNodeSelectorVolume) }} + allow-empty-node-selector-volume: {{ .Values.defaultSettings.allowEmptyNodeSelectorVolume }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowEmptyDiskSelectorVolume) }} + allow-empty-disk-selector-volume: {{ .Values.defaultSettings.allowEmptyDiskSelectorVolume }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowCollectingLonghornUsageMetrics) }} + allow-collecting-longhorn-usage-metrics: {{ .Values.defaultSettings.allowCollectingLonghornUsageMetrics }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableSnapshotPurge) }} + disable-snapshot-purge: {{ .Values.defaultSettings.disableSnapshotPurge }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU) }} + v2-data-engine-guaranteed-instance-manager-cpu: {{ .Values.defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotMaxCount) }} + snapshot-max-count: {{ .Values.defaultSettings.snapshotMaxCount }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineLogLevel) }} + v2-data-engine-log-level: {{ .Values.defaultSettings.v2DataEngineLogLevel }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineLogFlags) }} + v2-data-engine-log-flags: {{ .Values.defaultSettings.v2DataEngineLogFlags }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.freezeFilesystemForSnapshot) }} + freeze-filesystem-for-snapshot: {{ .Values.defaultSettings.freezeFilesystemForSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupSnapshotWhenDeleteBackup) }} + auto-cleanup-when-delete-backup: {{ .Values.defaultSettings.autoCleanupSnapshotWhenDeleteBackup }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.rwxVolumeFastFailover) }} + rwx-volume-fast-failover: {{ .Values.defaultSettings.rwxVolumeFastFailover}} + {{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/deployment-driver.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/deployment-driver.yaml new file mode 100644 index 0000000000..5683c759e7 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/deployment-driver.yaml @@ -0,0 +1,135 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: longhorn-driver-deployer + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + replicas: 1 + selector: + matchLabels: + app: longhorn-driver-deployer + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-driver-deployer + spec: + initContainers: + - name: wait-longhorn-manager + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + command: ['sh', '-c', 'while [ $(curl -m 1 -s -o /dev/null -w "%{http_code}" http://longhorn-backend:9500/v1) != "200" ]; do echo waiting; sleep 2; done'] + containers: + - name: longhorn-driver-deployer + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - -d + {{- if eq .Values.longhornDriver.log.format "json" }} + - -j + {{- end }} + - deploy-driver + - --manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }}" + - --manager-url + - http://longhorn-backend:9500/v1 + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + - name: SERVICE_ACCOUNT + valueFrom: + fieldRef: + fieldPath: spec.serviceAccountName + {{- if .Values.csi.kubeletRootDir }} + - name: KUBELET_ROOT_DIR + value: {{ .Values.csi.kubeletRootDir }} + {{- end }} + {{- if and .Values.image.csi.attacher.repository .Values.image.csi.attacher.tag }} + - name: CSI_ATTACHER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.attacher.repository }}:{{ .Values.image.csi.attacher.tag }}" + {{- end }} + {{- if and .Values.image.csi.provisioner.repository .Values.image.csi.provisioner.tag }} + - name: CSI_PROVISIONER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.provisioner.repository }}:{{ .Values.image.csi.provisioner.tag }}" + {{- end }} + {{- if and .Values.image.csi.nodeDriverRegistrar.repository .Values.image.csi.nodeDriverRegistrar.tag }} + - name: CSI_NODE_DRIVER_REGISTRAR_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.nodeDriverRegistrar.repository }}:{{ .Values.image.csi.nodeDriverRegistrar.tag }}" + {{- end }} + {{- if and .Values.image.csi.resizer.repository .Values.image.csi.resizer.tag }} + - name: CSI_RESIZER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.resizer.repository }}:{{ .Values.image.csi.resizer.tag }}" + {{- end }} + {{- if and .Values.image.csi.snapshotter.repository .Values.image.csi.snapshotter.tag }} + - name: CSI_SNAPSHOTTER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.snapshotter.repository }}:{{ .Values.image.csi.snapshotter.tag }}" + {{- end }} + {{- if and .Values.image.csi.livenessProbe.repository .Values.image.csi.livenessProbe.tag }} + - name: CSI_LIVENESS_PROBE_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.livenessProbe.repository }}:{{ .Values.image.csi.livenessProbe.tag }}" + {{- end }} + {{- if .Values.csi.attacherReplicaCount }} + - name: CSI_ATTACHER_REPLICA_COUNT + value: {{ .Values.csi.attacherReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.provisionerReplicaCount }} + - name: CSI_PROVISIONER_REPLICA_COUNT + value: {{ .Values.csi.provisionerReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.resizerReplicaCount }} + - name: CSI_RESIZER_REPLICA_COUNT + value: {{ .Values.csi.resizerReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.snapshotterReplicaCount }} + - name: CSI_SNAPSHOTTER_REPLICA_COUNT + value: {{ .Values.csi.snapshotterReplicaCount | quote }} + {{- end }} + {{- if .Values.enableGoCoverDir }} + - name: GOCOVERDIR + value: /go-cover-dir/ + volumeMounts: + - name: go-cover-dir + mountPath: /go-cover-dir/ + {{- end }} + + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornDriver.priorityClass }} + priorityClassName: {{ .Values.longhornDriver.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornDriver.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornDriver.tolerations }} +{{ default .Values.global.tolerations .Values.longhornDriver.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornDriver.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornDriver.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornDriver.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} + serviceAccountName: longhorn-service-account + securityContext: + runAsUser: 0 + {{- if .Values.enableGoCoverDir }} + volumes: + - name: go-cover-dir + hostPath: + path: /go-cover-dir/ + type: DirectoryOrCreate + {{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/deployment-ui.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/deployment-ui.yaml new file mode 100644 index 0000000000..e4f3e0f8f7 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/deployment-ui.yaml @@ -0,0 +1,186 @@ +{{- if .Values.openshift.enabled }} +{{- if .Values.openshift.ui.route }} +# https://github.com/openshift/oauth-proxy/blob/master/contrib/sidecar.yaml +# Create a proxy service account and ensure it will use the route "proxy" +# Create a secure connection to the proxy via a route +apiVersion: route.openshift.io/v1 +kind: Route +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: {{ .Values.openshift.ui.route }} + namespace: {{ include "release_namespace" . }} +spec: + to: + kind: Service + name: longhorn-ui + tls: + termination: reencrypt +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: longhorn-ui + namespace: {{ include "release_namespace" . }} + annotations: + service.alpha.openshift.io/serving-cert-secret-name: longhorn-ui-tls +spec: + ports: + - name: longhorn-ui + port: {{ .Values.openshift.ui.port | default 443 }} + targetPort: {{ .Values.openshift.ui.proxy | default 8443 }} + selector: + app: longhorn-ui +--- +{{- end }} +{{- end }} +apiVersion: apps/v1 +kind: Deployment +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: longhorn-ui + namespace: {{ include "release_namespace" . }} +spec: + replicas: {{ .Values.longhornUI.replicas }} + selector: + matchLabels: + app: longhorn-ui + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-ui + spec: + serviceAccountName: longhorn-ui-service-account + affinity: + podAntiAffinity: + preferredDuringSchedulingIgnoredDuringExecution: + - weight: 1 + podAffinityTerm: + labelSelector: + matchExpressions: + - key: app + operator: In + values: + - longhorn-ui + topologyKey: kubernetes.io/hostname + containers: + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + - name: oauth-proxy + {{- if .Values.image.openshift.oauthProxy.repository }} + image: {{ template "registry_url" . }}{{ .Values.image.openshift.oauthProxy.repository }}:{{ .Values.image.openshift.oauthProxy.tag }} + {{- else }} + image: "" + {{- end }} + imagePullPolicy: IfNotPresent + ports: + - containerPort: {{ .Values.openshift.ui.proxy | default 8443 }} + name: public + args: + - --https-address=:{{ .Values.openshift.ui.proxy | default 8443 }} + - --provider=openshift + - --openshift-service-account=longhorn-ui-service-account + - --upstream=http://localhost:8000 + - --tls-cert=/etc/tls/private/tls.crt + - --tls-key=/etc/tls/private/tls.key + - --cookie-secret=SECRET + - --openshift-sar={"namespace":"{{ include "release_namespace" . }}","group":"longhorn.io","resource":"setting","verb":"delete"} + volumeMounts: + - mountPath: /etc/tls/private + name: longhorn-ui-tls + {{- end }} + {{- end }} + - name: longhorn-ui + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.ui.repository }}:{{ .Values.image.longhorn.ui.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + volumeMounts: + - name : nginx-cache + mountPath: /var/cache/nginx/ + - name : nginx-config + mountPath: /var/config/nginx/ + - name: var-run + mountPath: /var/run/ + ports: + - containerPort: 8000 + name: http + env: + - name: LONGHORN_MANAGER_IP + value: "http://longhorn-backend:9500" + - name: LONGHORN_UI_PORT + value: "8000" + volumes: + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + - name: longhorn-ui-tls + secret: + secretName: longhorn-ui-tls + {{- end }} + {{- end }} + - emptyDir: {} + name: nginx-cache + - emptyDir: {} + name: nginx-config + - emptyDir: {} + name: var-run + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornUI.priorityClass }} + priorityClassName: {{ .Values.longhornUI.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornUI.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornUI.tolerations }} +{{ default .Values.global.tolerations .Values.longhornUI.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornUI.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornUI.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornUI.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} +--- +kind: Service +apiVersion: v1 +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + {{- if eq .Values.service.ui.type "Rancher-Proxy" }} + kubernetes.io/cluster-service: "true" + {{- end }} + name: longhorn-frontend + namespace: {{ include "release_namespace" . }} +spec: + {{- if eq .Values.service.ui.type "Rancher-Proxy" }} + type: ClusterIP + {{- else }} + type: {{ .Values.service.ui.type }} + {{- end }} + {{- if and .Values.service.ui.loadBalancerIP (eq .Values.service.ui.type "LoadBalancer") }} + loadBalancerIP: {{ .Values.service.ui.loadBalancerIP }} + {{- end }} + {{- if and (eq .Values.service.ui.type "LoadBalancer") .Values.service.ui.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.service.ui.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + selector: + app: longhorn-ui + ports: + - name: http + port: 80 + targetPort: http + {{- if .Values.service.ui.nodePort }} + nodePort: {{ .Values.service.ui.nodePort }} + {{- else }} + nodePort: null + {{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/ingress.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/ingress.yaml new file mode 100644 index 0000000000..61175e827b --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/ingress.yaml @@ -0,0 +1,37 @@ +{{- if .Values.ingress.enabled }} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: longhorn-ingress + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ingress + annotations: + {{- if .Values.ingress.secureBackends }} + ingress.kubernetes.io/secure-backends: "true" + {{- end }} + {{- range $key, $value := .Values.ingress.annotations }} + {{ $key }}: {{ $value | quote }} + {{- end }} +spec: + {{- if .Values.ingress.ingressClassName }} + ingressClassName: {{ .Values.ingress.ingressClassName }} + {{- end }} + rules: + - host: {{ .Values.ingress.host }} + http: + paths: + - path: {{ default "" .Values.ingress.path }} + pathType: {{ default "ImplementationSpecific" .Values.ingress.pathType }} + backend: + service: + name: longhorn-frontend + port: + number: 80 +{{- if .Values.ingress.tls }} + tls: + - hosts: + - {{ .Values.ingress.host }} + secretName: {{ .Values.ingress.tlsSecret }} +{{- end }} +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/backing-image-data-source-network-policy.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/backing-image-data-source-network-policy.yaml new file mode 100644 index 0000000000..7204d63caa --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/backing-image-data-source-network-policy.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: backing-image-data-source + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/backing-image-manager-network-policy.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/backing-image-manager-network-policy.yaml new file mode 100644 index 0000000000..119ebf08a1 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/backing-image-manager-network-policy.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: backing-image-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/instance-manager-networking.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/instance-manager-networking.yaml new file mode 100644 index 0000000000..332aa2c2fe --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/instance-manager-networking.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: instance-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: instance-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/manager-network-policy.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/manager-network-policy.yaml new file mode 100644 index 0000000000..6f94029a53 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/manager-network-policy.yaml @@ -0,0 +1,35 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + app: longhorn-ui + - podSelector: + matchLabels: + app: longhorn-csi-plugin + - podSelector: + matchLabels: + longhorn.io/managed-by: longhorn-manager + matchExpressions: + - { key: recurring-job.longhorn.io, operator: Exists } + - podSelector: + matchExpressions: + - { key: longhorn.io/job-task, operator: Exists } + - podSelector: + matchLabels: + app: longhorn-driver-deployer +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/recovery-backend-network-policy.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/recovery-backend-network-policy.yaml new file mode 100644 index 0000000000..37bf5f9bcf --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/recovery-backend-network-policy.yaml @@ -0,0 +1,17 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-recovery-backend + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/recovery-backend: longhorn-recovery-backend + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9503 +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/ui-frontend-network-policy.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/ui-frontend-network-policy.yaml new file mode 100644 index 0000000000..6f37065980 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/ui-frontend-network-policy.yaml @@ -0,0 +1,46 @@ +{{- if and .Values.networkPolicies.enabled .Values.ingress.enabled (not (eq .Values.networkPolicies.type "")) }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-ui-frontend + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-ui + policyTypes: + - Ingress + ingress: + - from: + {{- if eq .Values.networkPolicies.type "rke1"}} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress-nginx + podSelector: + matchLabels: + app.kubernetes.io/component: controller + app.kubernetes.io/instance: ingress-nginx + app.kubernetes.io/name: ingress-nginx + {{- else if eq .Values.networkPolicies.type "rke2" }} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + podSelector: + matchLabels: + app.kubernetes.io/component: controller + app.kubernetes.io/instance: rke2-ingress-nginx + app.kubernetes.io/name: rke2-ingress-nginx + {{- else if eq .Values.networkPolicies.type "k3s" }} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + podSelector: + matchLabels: + app.kubernetes.io/name: traefik + ports: + - port: 8000 + protocol: TCP + - port: 80 + protocol: TCP + {{- end }} +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/webhook-network-policy.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/webhook-network-policy.yaml new file mode 100644 index 0000000000..3812e0ffa3 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/network-policies/webhook-network-policy.yaml @@ -0,0 +1,33 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/conversion-webhook: longhorn-conversion-webhook + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9501 +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-admission-webhook + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/admission-webhook: longhorn-admission-webhook + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9502 +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/postupgrade-job.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/postupgrade-job.yaml new file mode 100644 index 0000000000..56efd38e9b --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/postupgrade-job.yaml @@ -0,0 +1,56 @@ +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": post-upgrade + "helm.sh/hook-delete-policy": hook-succeeded,before-hook-creation + name: longhorn-post-upgrade + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-post-upgrade + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-post-upgrade + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - post-upgrade + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: OnFailure + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/preupgrade-job.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/preupgrade-job.yaml new file mode 100644 index 0000000000..9f7a8a6aa6 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/preupgrade-job.yaml @@ -0,0 +1,64 @@ +{{- if and .Values.preUpgradeChecker.jobEnabled .Values.preUpgradeChecker.upgradeVersionCheck}} +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": pre-upgrade + "helm.sh/hook-delete-policy": hook-succeeded,before-hook-creation,hook-failed + name: longhorn-pre-upgrade + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-pre-upgrade + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-pre-upgrade + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + privileged: true + command: + - longhorn-manager + - pre-upgrade + volumeMounts: + - name: proc + mountPath: /host/proc/ + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + volumes: + - name: proc + hostPath: + path: /proc/ + restartPolicy: OnFailure + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/priorityclass.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/priorityclass.yaml new file mode 100644 index 0000000000..208adc84a2 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/priorityclass.yaml @@ -0,0 +1,9 @@ +apiVersion: scheduling.k8s.io/v1 +kind: PriorityClass +metadata: + name: "longhorn-critical" + labels: {{- include "longhorn.labels" . | nindent 4 }} +description: "Ensure Longhorn pods have the highest priority to prevent any unexpected eviction by the Kubernetes scheduler under node pressure" +globalDefault: false +preemptionPolicy: PreemptLowerPriority +value: 1000000000 diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/psp.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/psp.yaml new file mode 100644 index 0000000000..a2dfc05bef --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/psp.yaml @@ -0,0 +1,66 @@ +{{- if .Values.enablePSP }} +apiVersion: policy/v1beta1 +kind: PodSecurityPolicy +metadata: + name: longhorn-psp + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + privileged: true + allowPrivilegeEscalation: true + requiredDropCapabilities: + - NET_RAW + allowedCapabilities: + - SYS_ADMIN + hostNetwork: false + hostIPC: false + hostPID: true + runAsUser: + rule: RunAsAny + seLinux: + rule: RunAsAny + fsGroup: + rule: RunAsAny + supplementalGroups: + rule: RunAsAny + volumes: + - configMap + - downwardAPI + - emptyDir + - secret + - projected + - hostPath +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: longhorn-psp-role + labels: {{- include "longhorn.labels" . | nindent 4 }} + namespace: {{ include "release_namespace" . }} +rules: +- apiGroups: + - policy + resources: + - podsecuritypolicies + verbs: + - use + resourceNames: + - longhorn-psp +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: longhorn-psp-binding + labels: {{- include "longhorn.labels" . | nindent 4 }} + namespace: {{ include "release_namespace" . }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: longhorn-psp-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: default + namespace: {{ include "release_namespace" . }} +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/registry-secret.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/registry-secret.yaml new file mode 100644 index 0000000000..3c6b1dc510 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/registry-secret.yaml @@ -0,0 +1,13 @@ +{{- if .Values.privateRegistry.createSecret }} +{{- if .Values.privateRegistry.registrySecret }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .Values.privateRegistry.registrySecret }} + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +type: kubernetes.io/dockerconfigjson +data: + .dockerconfigjson: {{ template "secret" . }} +{{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/serviceaccount.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/serviceaccount.yaml new file mode 100644 index 0000000000..b0d6dd505b --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/serviceaccount.yaml @@ -0,0 +1,40 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-ui-service-account + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + {{- if not .Values.serviceAccount.annotations }} + annotations: + {{- end }} + serviceaccounts.openshift.io/oauth-redirectreference.primary: '{"kind":"OAuthRedirectReference","apiVersion":"v1","reference":{"kind":"Route","name":"longhorn-ui"}}' + {{- end }} + {{- end }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-support-bundle + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/servicemonitor.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/servicemonitor.yaml new file mode 100644 index 0000000000..3f32961332 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/servicemonitor.yaml @@ -0,0 +1,40 @@ +{{- if .Values.metrics.serviceMonitor.enabled -}} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: longhorn-prometheus-servicemonitor + namespace: {{ include "release_namespace" . }} + labels: + {{- include "longhorn.labels" . | nindent 4 }} + name: longhorn-prometheus-servicemonitor + {{- with .Values.metrics.serviceMonitor.additionalLabels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: + app: longhorn-manager + namespaceSelector: + matchNames: + - {{ include "release_namespace" . }} + endpoints: + - port: manager + {{- with .Values.metrics.serviceMonitor.interval }} + interval: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.relabelings }} + relabelings: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.metricRelabelings }} + metricRelabelings: + {{- toYaml . | nindent 8 }} + {{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/services.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/services.yaml new file mode 100644 index 0000000000..4c8c6bc687 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/services.yaml @@ -0,0 +1,47 @@ +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-conversion-webhook + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + longhorn.io/conversion-webhook: longhorn-conversion-webhook + ports: + - name: conversion-webhook + port: 9501 + targetPort: conversion-wh +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-admission-webhook + name: longhorn-admission-webhook + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + longhorn.io/admission-webhook: longhorn-admission-webhook + ports: + - name: admission-webhook + port: 9502 + targetPort: admission-wh +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-recovery-backend + name: longhorn-recovery-backend + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + longhorn.io/recovery-backend: longhorn-recovery-backend + ports: + - name: recovery-backend + port: 9503 + targetPort: recov-backend diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/storageclass.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/storageclass.yaml new file mode 100644 index 0000000000..884d38d5f3 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/storageclass.yaml @@ -0,0 +1,57 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-storageclass + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +data: + storageclass.yaml: | + kind: StorageClass + apiVersion: storage.k8s.io/v1 + metadata: + name: longhorn + annotations: + storageclass.kubernetes.io/is-default-class: {{ .Values.persistence.defaultClass | quote }} + provisioner: driver.longhorn.io + allowVolumeExpansion: true + reclaimPolicy: "{{ .Values.persistence.reclaimPolicy }}" + volumeBindingMode: Immediate + parameters: + numberOfReplicas: "{{ .Values.persistence.defaultClassReplicaCount }}" + staleReplicaTimeout: "30" + fromBackup: "" + {{- if .Values.persistence.defaultFsType }} + fsType: "{{ .Values.persistence.defaultFsType }}" + {{- end }} + {{- if .Values.persistence.defaultMkfsParams }} + mkfsParams: "{{ .Values.persistence.defaultMkfsParams }}" + {{- end }} + {{- if .Values.persistence.migratable }} + migratable: "{{ .Values.persistence.migratable }}" + {{- end }} + {{- if .Values.persistence.nfsOptions }} + nfsOptions: "{{ .Values.persistence.nfsOptions }}" + {{- end }} + {{- if .Values.persistence.backingImage.enable }} + backingImage: {{ .Values.persistence.backingImage.name }} + backingImageDataSourceType: {{ .Values.persistence.backingImage.dataSourceType }} + backingImageDataSourceParameters: {{ .Values.persistence.backingImage.dataSourceParameters }} + backingImageChecksum: {{ .Values.persistence.backingImage.expectedChecksum }} + {{- end }} + {{- if .Values.persistence.recurringJobSelector.enable }} + recurringJobSelector: '{{ .Values.persistence.recurringJobSelector.jobList }}' + {{- end }} + dataLocality: {{ .Values.persistence.defaultDataLocality | quote }} + {{- if .Values.persistence.defaultDiskSelector.enable }} + diskSelector: "{{ .Values.persistence.defaultDiskSelector.selector }}" + {{- end }} + {{- if .Values.persistence.defaultNodeSelector.enable }} + nodeSelector: "{{ .Values.persistence.defaultNodeSelector.selector }}" + {{- end }} + {{- if .Values.persistence.removeSnapshotsDuringFilesystemTrim }} + unmapMarkSnapChainRemoved: "{{ .Values.persistence.removeSnapshotsDuringFilesystemTrim }}" + {{- end }} + {{- if .Values.persistence.disableRevisionCounter }} + disableRevisionCounter: "{{ .Values.persistence.disableRevisionCounter }}" + dataEngine: "{{ .Values.persistence.dataEngine }}" + {{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/tls-secrets.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/tls-secrets.yaml new file mode 100644 index 0000000000..74c43426de --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/tls-secrets.yaml @@ -0,0 +1,16 @@ +{{- if .Values.ingress.enabled }} +{{- range .Values.ingress.secrets }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .name }} + namespace: {{ include "release_namespace" $ }} + labels: {{- include "longhorn.labels" $ | nindent 4 }} + app: longhorn +type: kubernetes.io/tls +data: + tls.crt: {{ .certificate | b64enc }} + tls.key: {{ .key | b64enc }} +--- +{{- end }} +{{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/uninstall-job.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/uninstall-job.yaml new file mode 100644 index 0000000000..1ab46207c3 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/uninstall-job.yaml @@ -0,0 +1,57 @@ +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": pre-delete + "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded + name: longhorn-uninstall + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-uninstall + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-uninstall + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - uninstall + - --force + env: + - name: LONGHORN_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: Never + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/userroles.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/userroles.yaml new file mode 100644 index 0000000000..57a68e130c --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/userroles.yaml @@ -0,0 +1,53 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-admin" + labels: + rbac.authorization.k8s.io/aggregate-to-admin: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", "settings/status", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "*" ] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-edit" + labels: + rbac.authorization.k8s.io/aggregate-to-edit: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", "settings/status", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "*" ] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-view" + labels: + rbac.authorization.k8s.io/aggregate-to-view: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", "settings/status", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "get", "list", "watch" ] diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/validate-install-crd.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/validate-install-crd.yaml new file mode 100644 index 0000000000..7bf81816d0 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/validate-install-crd.yaml @@ -0,0 +1,35 @@ +#{{- if gt (len (lookup "rbac.authorization.k8s.io/v1" "ClusterRole" "" "")) 0 -}} +# {{- $found := dict -}} +# {{- set $found "longhorn.io/v1beta1/BackingImageDataSource" false -}} +# {{- set $found "longhorn.io/v1beta1/BackingImageManager" false -}} +# {{- set $found "longhorn.io/v1beta1/BackingImage" false -}} +# {{- set $found "longhorn.io/v1beta2/BackupBackingImage" false -}} +# {{- set $found "longhorn.io/v1beta1/Backup" false -}} +# {{- set $found "longhorn.io/v1beta1/BackupTarget" false -}} +# {{- set $found "longhorn.io/v1beta1/BackupVolume" false -}} +# {{- set $found "longhorn.io/v1beta1/EngineImage" false -}} +# {{- set $found "longhorn.io/v1beta1/Engine" false -}} +# {{- set $found "longhorn.io/v1beta1/InstanceManager" false -}} +# {{- set $found "longhorn.io/v1beta1/Node" false -}} +# {{- set $found "longhorn.io/v1beta2/Orphan" false -}} +# {{- set $found "longhorn.io/v1beta1/RecurringJob" false -}} +# {{- set $found "longhorn.io/v1beta1/Replica" false -}} +# {{- set $found "longhorn.io/v1beta1/Setting" false -}} +# {{- set $found "longhorn.io/v1beta1/ShareManager" false -}} +# {{- set $found "longhorn.io/v1beta2/Snapshot" false -}} +# {{- set $found "longhorn.io/v1beta2/SupportBundle" false -}} +# {{- set $found "longhorn.io/v1beta2/SystemBackup" false -}} +# {{- set $found "longhorn.io/v1beta2/SystemRestore" false -}} +# {{- set $found "longhorn.io/v1beta2/VolumeAttachment" false -}} +# {{- set $found "longhorn.io/v1beta1/Volume" false -}} +# {{- range .Capabilities.APIVersions -}} +# {{- if hasKey $found (toString .) -}} +# {{- set $found (toString .) true -}} +# {{- end -}} +# {{- end -}} +# {{- range $_, $exists := $found -}} +# {{- if (eq $exists false) -}} +# {{- required "Required CRDs are missing. Please install the corresponding CRD chart before installing this chart." "" -}} +# {{- end -}} +# {{- end -}} +#{{- end -}} diff --git a/charts/longhorn/105.1.1+up1.7.3/templates/validate-psp-install.yaml b/charts/longhorn/105.1.1+up1.7.3/templates/validate-psp-install.yaml new file mode 100644 index 0000000000..0df98e3657 --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/templates/validate-psp-install.yaml @@ -0,0 +1,7 @@ +#{{- if gt (len (lookup "rbac.authorization.k8s.io/v1" "ClusterRole" "" "")) 0 -}} +#{{- if .Values.enablePSP }} +#{{- if not (.Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy") }} +#{{- fail "The target cluster does not have the PodSecurityPolicy API resource. Please disable PSPs in this chart before proceeding." -}} +#{{- end }} +#{{- end }} +#{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.1.1+up1.7.3/values.yaml b/charts/longhorn/105.1.1+up1.7.3/values.yaml new file mode 100644 index 0000000000..8061dc346b --- /dev/null +++ b/charts/longhorn/105.1.1+up1.7.3/values.yaml @@ -0,0 +1,531 @@ +# Default values for longhorn. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. +global: + # -- Toleration for nodes allowed to run user-deployed components such as Longhorn Manager, Longhorn UI, and Longhorn Driver Deployer. + tolerations: [] + # -- Node selector for nodes allowed to run user-deployed components such as Longhorn Manager, Longhorn UI, and Longhorn Driver Deployer. + nodeSelector: {} + cattle: + # -- Default system registry. + systemDefaultRegistry: "" + windowsCluster: + # -- Setting that allows Longhorn to run on a Rancher Windows cluster. + enabled: false + # -- Toleration for Linux nodes that can run user-deployed Longhorn components. + tolerations: + - key: "cattle.io/os" + value: "linux" + effect: "NoSchedule" + operator: "Equal" + # -- Node selector for Linux nodes that can run user-deployed Longhorn components. + nodeSelector: + kubernetes.io/os: "linux" + defaultSetting: + # -- Toleration for system-managed Longhorn components. + taintToleration: cattle.io/os=linux:NoSchedule + # -- Node selector for system-managed Longhorn components. + systemManagedComponentsNodeSelector: kubernetes.io/os:linux + +networkPolicies: + # -- Setting that allows you to enable network policies that control access to Longhorn pods. + enabled: false + # -- Distribution that determines the policy for allowing access for an ingress. (Options: "k3s", "rke2", "rke1") + type: "k3s" + +image: + longhorn: + engine: + # -- Repository for the Longhorn Engine image. + repository: rancher/mirrored-longhornio-longhorn-engine + # -- Tag for the Longhorn Engine image. + tag: v1.7.3 + manager: + # -- Repository for the Longhorn Manager image. + repository: rancher/mirrored-longhornio-longhorn-manager + # -- Tag for the Longhorn Manager image. + tag: v1.7.3 + ui: + # -- Repository for the Longhorn UI image. + repository: rancher/mirrored-longhornio-longhorn-ui + # -- Tag for the Longhorn UI image. + tag: v1.7.3 + instanceManager: + # -- Repository for the Longhorn Instance Manager image. + repository: rancher/mirrored-longhornio-longhorn-instance-manager + # -- Tag for the Longhorn Instance Manager image. + tag: v1.7.3 + shareManager: + # -- Repository for the Longhorn Share Manager image. + repository: rancher/mirrored-longhornio-longhorn-share-manager + # -- Tag for the Longhorn Share Manager image. + tag: v1.7.3 + backingImageManager: + # -- Repository for the Backing Image Manager image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-backing-image-manager + # -- Tag for the Backing Image Manager image. When unspecified, Longhorn uses the default value. + tag: v1.7.3 + supportBundleKit: + # -- Repository for the Longhorn Support Bundle Manager image. + repository: rancher/mirrored-longhornio-support-bundle-kit + # -- Tag for the Longhorn Support Bundle Manager image. + tag: v0.0.51 + csi: + attacher: + # -- Repository for the CSI attacher image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-attacher + # -- Tag for the CSI attacher image. When unspecified, Longhorn uses the default value. + tag: v4.8.0 + provisioner: + # -- Repository for the CSI Provisioner image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-provisioner + # -- Tag for the CSI Provisioner image. When unspecified, Longhorn uses the default value. + tag: v4.0.1-20250204 + nodeDriverRegistrar: + # -- Repository for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-node-driver-registrar + # -- Tag for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value. + tag: v2.13.0 + resizer: + # -- Repository for the CSI Resizer image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-resizer + # -- Tag for the CSI Resizer image. When unspecified, Longhorn uses the default value. + tag: v1.13.1 + snapshotter: + # -- Repository for the CSI Snapshotter image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-snapshotter + # -- Tag for the CSI Snapshotter image. When unspecified, Longhorn uses the default value. + tag: v7.0.2-20250204 + livenessProbe: + # -- Repository for the CSI liveness probe image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-livenessprobe + # -- Tag for the CSI liveness probe image. When unspecified, Longhorn uses the default value. + tag: v2.15.0 + openshift: + oauthProxy: + # -- Repository for the OAuth Proxy image. Specify the upstream image (for example, "quay.io/openshift/origin-oauth-proxy"). This setting applies only to OpenShift users. + repository: "" + # -- Tag for the OAuth Proxy image. Specify OCP/OKD version 4.1 or later (including version 4.15, which is available at quay.io/openshift/origin-oauth-proxy:4.15). This setting applies only to OpenShift users. + tag: "" + # -- Image pull policy that applies to all user-deployed Longhorn components, such as Longhorn Manager, Longhorn driver, and Longhorn UI. + pullPolicy: IfNotPresent + +service: + ui: + # -- Service type for Longhorn UI. (Options: "ClusterIP", "NodePort", "LoadBalancer", "Rancher-Proxy") + type: ClusterIP + # -- NodePort port number for Longhorn UI. When unspecified, Longhorn selects a free port between 30000 and 32767. + nodePort: null + manager: + # -- Service type for Longhorn Manager. + type: ClusterIP + # -- NodePort port number for Longhorn Manager. When unspecified, Longhorn selects a free port between 30000 and 32767. + nodePort: "" + +persistence: + # -- Setting that allows you to specify the default Longhorn StorageClass. + defaultClass: true + # -- Filesystem type of the default Longhorn StorageClass. + defaultFsType: ext4 + # -- mkfs parameters of the default Longhorn StorageClass. + defaultMkfsParams: "" + # -- Replica count of the default Longhorn StorageClass. + defaultClassReplicaCount: 3 + # -- Data locality of the default Longhorn StorageClass. (Options: "disabled", "best-effort") + defaultDataLocality: disabled + # -- Reclaim policy that provides instructions for handling of a volume after its claim is released. (Options: "Retain", "Delete") + reclaimPolicy: Delete + # -- Setting that allows you to enable live migration of a Longhorn volume from one node to another. + migratable: false + # -- Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the volume-head-xxx.img file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. + disableRevisionCounter: "true" + # -- Set NFS mount options for Longhorn StorageClass for RWX volumes + nfsOptions: "" + recurringJobSelector: + # -- Setting that allows you to enable the recurring job selector for a Longhorn StorageClass. + enable: false + # -- Recurring job selector for a Longhorn StorageClass. Ensure that quotes are used correctly when specifying job parameters. (Example: `[{"name":"backup", "isGroup":true}]`) + jobList: [] + backingImage: + # -- Setting that allows you to use a backing image in a Longhorn StorageClass. + enable: false + # -- Backing image to be used for creating and restoring volumes in a Longhorn StorageClass. When no backing images are available, specify the data source type and parameters that Longhorn can use to create a backing image. + name: ~ + # -- Data source type of a backing image used in a Longhorn StorageClass. + # If the backing image exists in the cluster, Longhorn uses this setting to verify the image. + # If the backing image does not exist, Longhorn creates one using the specified data source type. + dataSourceType: ~ + # -- Data source parameters of a backing image used in a Longhorn StorageClass. + # You can specify a JSON string of a map. (Example: `'{\"url\":\"https://backing-image-example.s3-region.amazonaws.com/test-backing-image\"}'`) + dataSourceParameters: ~ + # -- Expected SHA-512 checksum of a backing image used in a Longhorn StorageClass. + expectedChecksum: ~ + defaultDiskSelector: + # -- Setting that allows you to enable the disk selector for the default Longhorn StorageClass. + enable: false + # -- Disk selector for the default Longhorn StorageClass. Longhorn uses only disks with the specified tags for storing volume data. (Examples: "nvme,sata") + selector: "" + defaultNodeSelector: + # -- Setting that allows you to enable the node selector for the default Longhorn StorageClass. + enable: false + # -- Node selector for the default Longhorn StorageClass. Longhorn uses only nodes with the specified tags for storing volume data. (Examples: "storage,fast") + selector: "" + # -- Setting that allows you to enable automatic snapshot removal during filesystem trim for a Longhorn StorageClass. (Options: "ignored", "enabled", "disabled") + removeSnapshotsDuringFilesystemTrim: ignored + # -- Setting that allows you to specify the data engine version for the default Longhorn StorageClass. (Options: "v1", "v2") + dataEngine: v1 + +preUpgradeChecker: + # -- Setting that allows Longhorn to perform pre-upgrade checks. Disable this setting when installing Longhorn using Argo CD or other GitOps solutions. + jobEnabled: true + # -- Setting that allows Longhorn to perform upgrade version checks after starting the Longhorn Manager DaemonSet Pods. Disabling this setting also disables `preUpgradeChecker.jobEnabled`. Longhorn recommends keeping this setting enabled. + upgradeVersionCheck: true + +csi: + # -- kubelet root directory. When unspecified, Longhorn uses the default value. + kubeletRootDir: ~ + # -- Replica count of the CSI Attacher. When unspecified, Longhorn uses the default value ("3"). + attacherReplicaCount: ~ + # -- Replica count of the CSI Provisioner. When unspecified, Longhorn uses the default value ("3"). + provisionerReplicaCount: ~ + # -- Replica count of the CSI Resizer. When unspecified, Longhorn uses the default value ("3"). + resizerReplicaCount: ~ + # -- Replica count of the CSI Snapshotter. When unspecified, Longhorn uses the default value ("3"). + snapshotterReplicaCount: ~ + +defaultSettings: + # -- Endpoint used to access the backupstore. (Options: "NFS", "CIFS", "AWS", "GCP", "AZURE") + backupTarget: ~ + # -- Name of the Kubernetes secret associated with the backup target. + backupTargetCredentialSecret: ~ + # -- Setting that allows Longhorn to automatically attach a volume and create snapshots or backups when recurring jobs are run. + allowRecurringJobWhileVolumeDetached: ~ + # -- Setting that allows Longhorn to automatically create a default disk only on nodes with the label "node.longhorn.io/create-default-disk=true" (if no other disks exist). When this setting is disabled, Longhorn creates a default disk on each node that is added to the cluster. + createDefaultDiskLabeledNodes: ~ + # -- Default path for storing data on a host. The default value is "/var/lib/longhorn/". + defaultDataPath: ~ + # -- Default data locality. A Longhorn volume has data locality if a local replica of the volume exists on the same node as the pod that is using the volume. + defaultDataLocality: ~ + # -- Setting that allows scheduling on nodes with healthy replicas of the same volume. This setting is disabled by default. + replicaSoftAntiAffinity: ~ + # -- Setting that automatically rebalances replicas when an available node is discovered. + replicaAutoBalance: ~ + # -- Percentage of storage that can be allocated relative to hard drive capacity. The default value is "100". + storageOverProvisioningPercentage: ~ + # -- Percentage of minimum available disk capacity. When the minimum available capacity exceeds the total available capacity, the disk becomes unschedulable until more space is made available for use. The default value is "25". + storageMinimalAvailablePercentage: ~ + # -- Percentage of disk space that is not allocated to the default disk on each new Longhorn node. + storageReservedPercentageForDefaultDisk: ~ + # -- Upgrade Checker that periodically checks for new Longhorn versions. When a new version is available, a notification appears on the Longhorn UI. This setting is enabled by default + upgradeChecker: ~ + # -- Default number of replicas for volumes created using the Longhorn UI. For Kubernetes configuration, modify the `numberOfReplicas` field in the StorageClass. The default value is "3". + defaultReplicaCount: ~ + # -- Default Longhorn StorageClass. "storageClassName" is assigned to PVs and PVCs that are created for an existing Longhorn volume. "storageClassName" can also be used as a label, so it is possible to use a Longhorn StorageClass to bind a workload to an existing PV without creating a Kubernetes StorageClass object. The default value is "longhorn-static". + defaultLonghornStaticStorageClass: ~ + # -- Number of seconds that Longhorn waits before checking the backupstore for new backups. The default value is "300". When the value is "0", polling is disabled. + backupstorePollInterval: ~ + # -- Number of minutes that Longhorn keeps a failed backup resource. When the value is "0", automatic deletion is disabled. + failedBackupTTL: ~ + # -- Number of minutes that Longhorn allows for the backup execution. The default value is "1". + backupExecutionTimeout: ~ + # -- Setting that restores recurring jobs from a backup volume on a backup target and creates recurring jobs if none exist during backup restoration. + restoreVolumeRecurringJobs: ~ + # -- Maximum number of successful recurring backup and snapshot jobs to be retained. When the value is "0", a history of successful recurring jobs is not retained. + recurringSuccessfulJobsHistoryLimit: ~ + # -- Maximum number of failed recurring backup and snapshot jobs to be retained. When the value is "0", a history of failed recurring jobs is not retained. + recurringFailedJobsHistoryLimit: ~ + # -- Maximum number of snapshots or backups to be retained. + recurringJobMaxRetention: ~ + # -- Maximum number of failed support bundles that can exist in the cluster. When the value is "0", Longhorn automatically purges all failed support bundles. + supportBundleFailedHistoryLimit: ~ + # -- Taint or toleration for system-managed Longhorn components. + # Specify values using a semicolon-separated list in `kubectl taint` syntax (Example: key1=value1:effect; key2=value2:effect). + taintToleration: ~ + # -- Node selector for system-managed Longhorn components. + systemManagedComponentsNodeSelector: ~ + # -- PriorityClass for system-managed Longhorn components. + # This setting can help prevent Longhorn components from being evicted under Node Pressure. + # Notice that this will be applied to Longhorn user-deployed components by default if there are no priority class values set yet, such as `longhornManager.priorityClass`. + priorityClass: &defaultPriorityClassNameRef "longhorn-critical" + # -- Setting that allows Longhorn to automatically salvage volumes when all replicas become faulty (for example, when the network connection is interrupted). Longhorn determines which replicas are usable and then uses these replicas for the volume. This setting is enabled by default. + autoSalvage: ~ + # -- Setting that allows Longhorn to automatically delete a workload pod that is managed by a controller (for example, daemonset) whenever a Longhorn volume is detached unexpectedly (for example, during Kubernetes upgrades). After deletion, the controller restarts the pod and then Kubernetes handles volume reattachment and remounting. + autoDeletePodWhenVolumeDetachedUnexpectedly: ~ + # -- Setting that prevents Longhorn Manager from scheduling replicas on a cordoned Kubernetes node. This setting is enabled by default. + disableSchedulingOnCordonedNode: ~ + # -- Setting that allows Longhorn to schedule new replicas of a volume to nodes in the same zone as existing healthy replicas. Nodes that do not belong to any zone are treated as existing in the zone that contains healthy replicas. When identifying zones, Longhorn relies on the label "topology.kubernetes.io/zone=" in the Kubernetes node object. + replicaZoneSoftAntiAffinity: ~ + # -- Setting that allows scheduling on disks with existing healthy replicas of the same volume. This setting is enabled by default. + replicaDiskSoftAntiAffinity: ~ + # -- Policy that defines the action Longhorn takes when a volume is stuck with a StatefulSet or Deployment pod on a node that failed. + nodeDownPodDeletionPolicy: ~ + # -- Policy that defines the action Longhorn takes when a node with the last healthy replica of a volume is drained. + nodeDrainPolicy: ~ + # -- Setting that allows automatic detaching of manually-attached volumes when a node is cordoned. + detachManuallyAttachedVolumesWhenCordoned: ~ + # -- Number of seconds that Longhorn waits before reusing existing data on a failed replica instead of creating a new replica of a degraded volume. + replicaReplenishmentWaitInterval: ~ + # -- Maximum number of replicas that can be concurrently rebuilt on each node. + concurrentReplicaRebuildPerNodeLimit: ~ + # -- Maximum number of volumes that can be concurrently restored on each node using a backup. When the value is "0", restoration of volumes using a backup is disabled. + concurrentVolumeBackupRestorePerNodeLimit: ~ + # -- Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the "volume-head-xxx.img" file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. This setting applies only to volumes created using the Longhorn UI. + disableRevisionCounter: "true" + # -- Image pull policy for system-managed pods, such as Instance Manager, engine images, and CSI Driver. Changes to the image pull policy are applied only after the system-managed pods restart. + systemManagedPodsImagePullPolicy: ~ + # -- Setting that allows you to create and attach a volume without having all replicas scheduled at the time of creation. + allowVolumeCreationWithDegradedAvailability: ~ + # -- Setting that allows Longhorn to automatically clean up the system-generated snapshot after replica rebuilding is completed. + autoCleanupSystemGeneratedSnapshot: ~ + # -- Setting that allows Longhorn to automatically clean up the snapshot generated by a recurring backup job. + autoCleanupRecurringJobBackupSnapshot: ~ + # -- Maximum number of engines that are allowed to concurrently upgrade on each node after Longhorn Manager is upgraded. When the value is "0", Longhorn does not automatically upgrade volume engines to the new default engine image version. + concurrentAutomaticEngineUpgradePerNodeLimit: ~ + # -- Number of minutes that Longhorn waits before cleaning up the backing image file when no replicas in the disk are using it. + backingImageCleanupWaitInterval: ~ + # -- Number of seconds that Longhorn waits before downloading a backing image file again when the status of all image disk files changes to "failed" or "unknown". + backingImageRecoveryWaitInterval: ~ + # -- Percentage of the total allocatable CPU resources on each node to be reserved for each instance manager pod when the V1 Data Engine is enabled. The default value is "12". + guaranteedInstanceManagerCPU: ~ + # -- Setting that notifies Longhorn that the cluster is using the Kubernetes Cluster Autoscaler. + kubernetesClusterAutoscalerEnabled: ~ + # -- Setting that allows Longhorn to automatically delete an orphaned resource and the corresponding data (for example, stale replicas). Orphaned resources on failed or unknown nodes are not automatically cleaned up. + orphanAutoDeletion: ~ + # -- Storage network for in-cluster traffic. When unspecified, Longhorn uses the Kubernetes cluster network. + storageNetwork: ~ + # -- Flag that prevents accidental uninstallation of Longhorn. + deletingConfirmationFlag: ~ + # -- Timeout between the Longhorn Engine and replicas. Specify a value between "8" and "30" seconds. The default value is "8". + engineReplicaTimeout: ~ + # -- Setting that allows you to enable and disable snapshot hashing and data integrity checks. + snapshotDataIntegrity: ~ + # -- Setting that allows disabling of snapshot hashing after snapshot creation to minimize impact on system performance. + snapshotDataIntegrityImmediateCheckAfterSnapshotCreation: ~ + # -- Setting that defines when Longhorn checks the integrity of data in snapshot disk files. You must use the Unix cron expression format. + snapshotDataIntegrityCronjob: ~ + # -- Setting that allows Longhorn to automatically mark the latest snapshot and its parent files as removed during a filesystem trim. Longhorn does not remove snapshots containing multiple child files. + removeSnapshotsDuringFilesystemTrim: ~ + # -- Setting that allows fast rebuilding of replicas using the checksum of snapshot disk files. Before enabling this setting, you must set the snapshot-data-integrity value to "enable" or "fast-check". + fastReplicaRebuildEnabled: ~ + # -- Number of seconds that an HTTP client waits for a response from a File Sync server before considering the connection to have failed. + replicaFileSyncHttpClientTimeout: ~ + # -- Number of seconds that Longhorn allows for the completion of replica rebuilding and snapshot cloning operations. + longGRPCTimeOut: ~ + # -- Log levels that indicate the type and severity of logs in Longhorn Manager. The default value is "Info". (Options: "Panic", "Fatal", "Error", "Warn", "Info", "Debug", "Trace") + logLevel: ~ + # -- Setting that allows you to specify a backup compression method. + backupCompressionMethod: ~ + # -- Maximum number of worker threads that can concurrently run for each backup. + backupConcurrentLimit: ~ + # -- Maximum number of worker threads that can concurrently run for each restore operation. + restoreConcurrentLimit: ~ + # -- Setting that allows you to enable the V1 Data Engine. + v1DataEngine: ~ + # -- Setting that allows you to enable the V2 Data Engine, which is based on the Storage Performance Development Kit (SPDK). The V2 Data Engine is a preview feature and should not be used in production environments. + v2DataEngine: ~ + # -- Setting that allows you to configure maximum huge page size (in MiB) for the V2 Data Engine. + v2DataEngineHugepageLimit: ~ + # -- Number of millicpus on each node to be reserved for each Instance Manager pod when the V2 Data Engine is enabled. The default value is "1250". + v2DataEngineGuaranteedInstanceManagerCPU: ~ + # -- Setting that allows scheduling of empty node selector volumes to any node. + allowEmptyNodeSelectorVolume: ~ + # -- Setting that allows scheduling of empty disk selector volumes to any disk. + allowEmptyDiskSelectorVolume: ~ + # -- Setting that allows Longhorn to periodically collect anonymous usage data for product improvement purposes. Longhorn sends collected data to the [Upgrade Responder](https://github.com/longhorn/upgrade-responder) server, which is the data source of the Longhorn Public Metrics Dashboard (https://metrics.longhorn.io). The Upgrade Responder server does not store data that can be used to identify clients, including IP addresses. + allowCollectingLonghornUsageMetrics: ~ + # -- Setting that temporarily prevents all attempts to purge volume snapshots. + disableSnapshotPurge: ~ + # -- Maximum snapshot count for a volume. The value should be between 2 to 250 + snapshotMaxCount: ~ + # -- Setting that allows you to configure the log level of the SPDK target daemon (spdk_tgt) of the V2 Data Engine. + v2DataEngineLogLevel: ~ + # -- Setting that allows you to configure the log flags of the SPDK target daemon (spdk_tgt) of the V2 Data Engine. + v2DataEngineLogFlags: ~ + # -- Setting that freezes the filesystem on the root partition before a snapshot is created. + freezeFilesystemForSnapshot: ~ + # -- Setting that automatically cleans up the snapshot when the backup is deleted. + autoCleanupSnapshotWhenDeleteBackup: ~ + # -- Turn on logic to detect and move RWX volumes quickly on node failure. + rwxVolumeFastFailover: ~ + +privateRegistry: + # -- Setting that allows you to create a private registry secret. + createSecret: ~ + # -- URL of a private registry. When unspecified, Longhorn uses the default system registry. + registryUrl: ~ + # -- User account used for authenticating with a private registry. + registryUser: ~ + # -- Password for authenticating with a private registry. + registryPasswd: ~ + # -- Kubernetes secret that allows you to pull images from a private registry. This setting applies only when creation of private registry secrets is enabled. You must include the private registry name in the secret name. + registrySecret: ~ + +longhornManager: + log: + # -- Format of Longhorn Manager logs. (Options: "plain", "json") + format: plain + # -- PriorityClass for Longhorn Manager. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn Manager on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn Manager DaemonSet, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn Manager. Specify the nodes allowed to run Longhorn Manager. + nodeSelector: {} + ## If you want to set node selector for Longhorn Manager DaemonSet, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + # -- Annotation for the Longhorn Manager service. + serviceAnnotations: {} + ## If you want to set annotations for the Longhorn Manager service, delete the `{}` in the line above + ## and uncomment this example block + # annotation-key1: "annotation-value1" + # annotation-key2: "annotation-value2" + +longhornDriver: + log: + # -- Format of longhorn-driver logs. (Options: "plain", "json") + format: plain + # -- PriorityClass for Longhorn Driver. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn Driver on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn Driver Deployer Deployment, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn Driver. Specify the nodes allowed to run Longhorn Driver. + nodeSelector: {} + ## If you want to set node selector for Longhorn Driver Deployer Deployment, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + +longhornUI: + # -- Replica count for Longhorn UI. + replicas: 2 + # -- PriorityClass for Longhorn UI. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn UI on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn UI Deployment, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn UI. Specify the nodes allowed to run Longhorn UI. + nodeSelector: {} + ## If you want to set node selector for Longhorn UI Deployment, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + +ingress: + # -- Setting that allows Longhorn to generate ingress records for the Longhorn UI service. + enabled: false + + # -- IngressClass resource that contains ingress configuration, including the name of the Ingress controller. + # ingressClassName can replace the kubernetes.io/ingress.class annotation used in earlier Kubernetes releases. + ingressClassName: ~ + + # -- Hostname of the Layer 7 load balancer. + host: sslip.io + + # -- Setting that allows you to enable TLS on ingress records. + tls: false + + # -- Setting that allows you to enable secure connections to the Longhorn UI service via port 443. + secureBackends: false + + # -- TLS secret that contains the private key and certificate to be used for TLS. This setting applies only when TLS is enabled on ingress records. + tlsSecret: longhorn.local-tls + + # -- Default ingress path. You can access the Longhorn UI by following the full ingress path {{host}}+{{path}}. + path: / + + # -- Ingress path type. To maintain backward compatibility, the default value is "ImplementationSpecific". + pathType: ImplementationSpecific + + ## If you're using kube-lego, you will want to add: + ## kubernetes.io/tls-acme: true + ## + ## For a full list of possible ingress annotations, please see + ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/annotations.md + ## + ## If tls is set to true, annotation ingress.kubernetes.io/secure-backends: "true" will automatically be set + # -- Ingress annotations in the form of key-value pairs. + annotations: + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: true + + # -- Secret that contains a TLS private key and certificate. Use secrets if you want to use your own certificates to secure ingresses. + secrets: + ## If you're providing your own certificates, please use this to add the certificates as secrets + ## key and certificate should start with -----BEGIN CERTIFICATE----- or + ## -----BEGIN RSA PRIVATE KEY----- + ## + ## name should line up with a tlsSecret set further up + ## If you're using kube-lego, this is unneeded, as it will create the secret for you if it is not set + ## + ## It is also possible to create and manage the certificates outside of this helm chart + ## Please see README.md for more information + # - name: longhorn.local-tls + # key: + # certificate: + +# -- Setting that allows you to enable pod security policies (PSPs) that allow privileged Longhorn pods to start. This setting applies only to clusters running Kubernetes 1.25 and earlier, and with the built-in Pod Security admission controller enabled. +enablePSP: false + +# -- Specify override namespace, specifically this is useful for using longhorn as sub-chart and its release namespace is not the `longhorn-system`. +namespaceOverride: "" + +# -- Annotation for the Longhorn Manager DaemonSet pods. This setting is optional. +annotations: {} + +serviceAccount: + # -- Annotations to add to the service account + annotations: {} + +metrics: + serviceMonitor: + # -- Setting that allows the creation of a Prometheus ServiceMonitor resource for Longhorn Manager components. + enabled: false + # -- Additional labels for the Prometheus ServiceMonitor resource. + additionalLabels: {} + # -- Annotations for the Prometheus ServiceMonitor resource. + annotations: {} + # -- Interval at which Prometheus scrapes the metrics from the target. + interval: "" + # -- Timeout after which Prometheus considers the scrape to be failed. + scrapeTimeout: "" + # -- Configures the relabeling rules to apply the target’s metadata labels. See the [Prometheus Operator + # documentation](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.Endpoint) for + # formatting details. + relabelings: [] + # -- Configures the relabeling rules to apply to the samples before ingestion. See the [Prometheus Operator + # documentation](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.Endpoint) for + # formatting details. + metricRelabelings: [] + +## openshift settings +openshift: + # -- Setting that allows Longhorn to integrate with OpenShift. + enabled: false + ui: + # -- Route for connections between Longhorn and the OpenShift web console. + route: "longhorn-ui" + # -- Port for accessing the OpenShift web console. + port: 443 + # -- Port for proxy that provides access to the OpenShift web console. + proxy: 8443 + +# -- Setting that allows Longhorn to generate code coverage profiles. +enableGoCoverDir: false diff --git a/index.yaml b/index.yaml index dcf6dd32d2..9d138765cc 100755 --- a/index.yaml +++ b/index.yaml @@ -4554,6 +4554,49 @@ entries: - assets/harvester-csi-driver/harvester-csi-driver-101.0.0+up0.1.14.tgz version: 101.0.0+up0.1.14 longhorn: + - annotations: + catalog.cattle.io/auto-install: longhorn-crd=match + catalog.cattle.io/certified: rancher + catalog.cattle.io/display-name: Longhorn + catalog.cattle.io/kube-version: '>= 1.23.0-0' + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/permits-os: linux,windows + catalog.cattle.io/provides-gvr: longhorn.io/v1beta1 + catalog.cattle.io/rancher-version: '>= 2.10.0-0 < 2.11.0-0' + catalog.cattle.io/release-name: longhorn + catalog.cattle.io/type: cluster-tool + catalog.cattle.io/upstream-version: 1.7.3 + apiVersion: v1 + appVersion: v1.7.3 + created: "2025-03-02T13:05:19.203084359-03:00" + description: Longhorn is a distributed block storage system for Kubernetes. + digest: 02eed84e8ea57f2e8eebfd1eca9d1ad5a209076e81c311500c1c4d00c84750fb + home: https://github.com/longhorn/longhorn + icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/longhorn/icon/color/longhorn-icon-color.png + keywords: + - longhorn + - storage + - distributed + - block + - device + - iscsi + - nfs + maintainers: + - email: maintainers@longhorn.io + name: Longhorn maintainers + name: longhorn + sources: + - https://github.com/longhorn/longhorn + - https://github.com/longhorn/longhorn-engine + - https://github.com/longhorn/longhorn-instance-manager + - https://github.com/longhorn/longhorn-share-manager + - https://github.com/longhorn/longhorn-manager + - https://github.com/longhorn/longhorn-ui + - https://github.com/longhorn/longhorn-tests + - https://github.com/longhorn/backing-image-manager + urls: + - assets/longhorn/longhorn-105.1.1+up1.7.3.tgz + version: 105.1.1+up1.7.3 - annotations: catalog.cattle.io/auto-install: longhorn-crd=match catalog.cattle.io/certified: rancher diff --git a/release.yaml b/release.yaml index 8b13789179..6cc0cbec20 100644 --- a/release.yaml +++ b/release.yaml @@ -1 +1,2 @@ - +longhorn: + - 105.1.1+up1.7.3 From 7c0590a4534afec17c044353039145d2f01225a3 Mon Sep 17 00:00:00 2001 From: nicholasSUSE Date: Sun, 2 Mar 2025 13:05:29 -0300 Subject: [PATCH 3/9] fp: longhorn-105.1.0+up1.7.2 --- assets/longhorn/longhorn-105.1.0+up1.7.2.tgz | Bin 0 -> 31980 bytes charts/longhorn/105.1.0+up1.7.2/.helmignore | 21 + charts/longhorn/105.1.0+up1.7.2/Chart.yaml | 39 + charts/longhorn/105.1.0+up1.7.2/README.md | 50 + charts/longhorn/105.1.0+up1.7.2/app-readme.md | 27 + .../longhorn/105.1.0+up1.7.2/questions.yaml | 974 ++++++++++++++++++ .../105.1.0+up1.7.2/templates/NOTES.txt | 5 + .../105.1.0+up1.7.2/templates/_helpers.tpl | 66 ++ .../templates/clusterrole.yaml | 77 ++ .../templates/clusterrolebinding.yaml | 49 + .../templates/daemonset-sa.yaml | 180 ++++ .../templates/default-setting.yaml | 244 +++++ .../templates/deployment-driver.yaml | 132 +++ .../templates/deployment-ui.yaml | 186 ++++ .../105.1.0+up1.7.2/templates/ingress.yaml | 37 + ...king-image-data-source-network-policy.yaml | 27 + .../backing-image-manager-network-policy.yaml | 27 + .../instance-manager-networking.yaml | 27 + .../manager-network-policy.yaml | 35 + .../recovery-backend-network-policy.yaml | 17 + .../ui-frontend-network-policy.yaml | 46 + .../webhook-network-policy.yaml | 33 + .../templates/postupgrade-job.yaml | 56 + .../templates/preupgrade-job.yaml | 64 ++ .../templates/priorityclass.yaml | 9 + .../105.1.0+up1.7.2/templates/psp.yaml | 66 ++ .../templates/registry-secret.yaml | 13 + .../templates/serviceaccount.yaml | 40 + .../templates/servicemonitor.yaml | 40 + .../105.1.0+up1.7.2/templates/services.yaml | 47 + .../templates/storageclass.yaml | 57 + .../templates/tls-secrets.yaml | 16 + .../templates/uninstall-job.yaml | 57 + .../105.1.0+up1.7.2/templates/userroles.yaml | 53 + .../templates/validate-install-crd.yaml | 35 + .../templates/validate-psp-install.yaml | 7 + charts/longhorn/105.1.0+up1.7.2/values.yaml | 526 ++++++++++ index.yaml | 43 + release.yaml | 1 + 39 files changed, 3429 insertions(+) create mode 100644 assets/longhorn/longhorn-105.1.0+up1.7.2.tgz create mode 100644 charts/longhorn/105.1.0+up1.7.2/.helmignore create mode 100644 charts/longhorn/105.1.0+up1.7.2/Chart.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/README.md create mode 100644 charts/longhorn/105.1.0+up1.7.2/app-readme.md create mode 100644 charts/longhorn/105.1.0+up1.7.2/questions.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/NOTES.txt create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/_helpers.tpl create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/clusterrole.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/clusterrolebinding.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/daemonset-sa.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/default-setting.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/deployment-driver.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/deployment-ui.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/ingress.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/network-policies/backing-image-data-source-network-policy.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/network-policies/backing-image-manager-network-policy.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/network-policies/instance-manager-networking.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/network-policies/manager-network-policy.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/network-policies/recovery-backend-network-policy.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/network-policies/ui-frontend-network-policy.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/network-policies/webhook-network-policy.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/postupgrade-job.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/preupgrade-job.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/priorityclass.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/psp.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/registry-secret.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/serviceaccount.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/servicemonitor.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/services.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/storageclass.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/tls-secrets.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/uninstall-job.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/userroles.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/validate-install-crd.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/templates/validate-psp-install.yaml create mode 100644 charts/longhorn/105.1.0+up1.7.2/values.yaml diff --git a/assets/longhorn/longhorn-105.1.0+up1.7.2.tgz b/assets/longhorn/longhorn-105.1.0+up1.7.2.tgz new file mode 100644 index 0000000000000000000000000000000000000000..169d2d70e6aaccaabb95778173eed758599982b9 GIT binary patch literal 31980 zcmV)XK&`(YiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMZ%b{jXcFgkw^p8}iC?ARVPMcwS#+@JS4iXe;@wu_xt7lcMtY={)H|8;G7)uc#qNIaOuTu3sjEuIoSqf!J+3{Xsy>~`yhCK0<4^`$wxrV$ar zumZ7qX|;wW}|JAE|@^uN@fJIw>)Bqmr8gR6KEuH-x=0~E%Ykc0=4 zvADKamI}!Up5*}T^j`LMJ2<63*f-ZZ9h|1#Pbd))5ptSJcxR^#QGqausF0kFGD#vd zidlGtgk&5~2-4U`W5&_<*@*CjNFsWjDO2N_N|}nm_V$FzX*TMGY_{zX~p6h zZCg?jA;pryBOG4QWD?LBp5&0{Yp8$F+v)ZHlBIgBd}#*1|%B<3yb&=weERX6=7JeETLCGd{yoarZHei7IeR z!WeUct}&;06cd3YLnDGxECh)VO(a8emT@G>ER8WR{YlJ5I93A36BGpKg2jY`5CYvN zEFuEoIA%8_QmyeUL5j%-5lLeh#<|F+iU_>kVDTMB&hYYA4cc zw46-T?lkW~3H{O(IWwOIsN03FM%X#hB7<(zw0cgYq{#%yDVBQF-eAn=S%NS+)8Y;K zQMYB~kDh6aB#Jnq0UG025Wk1g?7vasm%%c08sek|#}0-Z*|sZxD$T0^T@f|hT>4?6 zYrY{(`UBJj$uECR#$yu70qVYE=i!t@SxoYeELDA|+3249GsAJ$A5xWS?mnsl2{)!Qb7wq)afJyq{1PKX-J819H@@U=PXkMt_c^JnkY3@%`CD+auy>ThC~48bFil@ z0;ns5uNSM892N4Rsfb9Wge1^3(f!N;I{=S@&h!HB5=4^;Cqnel)Ay<2TivTY(cMB_ zenoc8|2y4hio1bI0G~S@kX+QzEuYt9p#{Fe;y)uP6I3#;0a0+d@tr_%1dZ9*;jX+> z{I+M5bH+&&*xo1$%0i}3lX%juFNr5kAyL1LB-R>!!-(%V04x738$oSvY{^=iP#{eW7bjx0?X zm)~Sb6qE0%Y)>J&BGNVQMk)q~U<7RiS5z)1lNR0UvG#lY-u{6SIE7(PSW2v5SvJ5^c58V>A=o3Uwey8fD27oycHUr)wL~RNz%dZ`3M1oT>WwNa2HlXJ`FaDq?^1xh#rcHvUQT4Ld@9h?s zXH2h2LWCG{Hd?A5D5z`&#S2H|!SH6ggtidvY?0hl>_w&yka8+xj$ky|`VW3q+1|IF|lbY0u~Hsf?clK}cx?EZG% zeb&?VJYm#boTjnTWmyu>mGb&NCCRy}3}y*YHv!#l6J{5H|NdyW{r>x7WUS<9zqf-J zM=@4(`;;bOoJ9&A@B6_Px|z~&3bw~c(u|#bKI#3O)IaruY7$uBQi;rm*$5tiR zHUiU_WJ*0>ZpGPZV+qtdNy!>`d8!~&0D#qEK0v4AcT5gB5hRhFjv)M+hOjQJ{%A}Z z@E%luZG!Sz^lb*l>UTQqZlSK)poWY~_4gZwqi=AmR3)x{8w+1B)U*U$X~TkRBJbWd zgh0$pve}66Di{maoHh^%gwdE2qMI2Jc|%Bo_WJ#PAJDY7`|`!ho|7U}j{}rsaoj0c z1eV~$Oh)gngR<@1)5yBrPA651L`ah8Nnd8a5*`b&>?>CT^ik$fj0G$JQviMskmQ*& zSiPn(F_vY(9viRJ;%jjMNF}#&-!?hB8Vi(Sj%P#?E>>;w?bTQeRc+y~*E5pFG{h)m zSt3_$5`LQ&j#L8!wC5~#SYi~j5XV%`+coU3vWN<>1FD5IB0>gaJXY)MS>C(q;f?8F zfNX_)U}22utiXk=BLbLWcosruK#)_MM6sd>Hbxj-vpAa(gvTH!NP%=yR3PJ45EWoO zBNEd@L3&JLA_)M=b^n$L=`Zc=r)tkdGdeN$W&q1!&A>P2Y=&4ufZ&0(CQMHCs?=3g zQzc7kp=*OQy;*ajRToVQgu}8@?UB(OrJP*D35^2+dY9ao4HQ?u;Zzc1=?BazkPNV9 zg$o>C;|WwSAIf4w%2fjrb{RfGy1WwWKow zzu@}~7HGyIU@y;LsRLs%W7o?-pT%W@L_ih>(VT?rn&`73gR(P&tRs!90qUyN-}SJJ z-n~9YGrg?RoYHDZAHJOZ`2Uy=MF*i|EOH9#YJ$o*r^)1RY*akhXh~9foTd@<3mX*= z6>#%%w^n)oG|DcrRhvU6iO4w7aQ-u6k_d#k!Fk9yC!vhz=mw}o^J3e6&ii`k>4_HQ z2I%8YpSlU2k?x>7!r@hxs)b0!x142Zcc5nF^FKc7-S-zZdP9XY2bR7)uN@*YK@hg} zj9f{RwJ`Thp^*~Vg`8k5gC&ttP9*~z8{$~hrCwzTD*~x8?8L&Y;wGmUwRVcpTb1h6 z+hza{xrl~gohpa{$_hfv77RW&|KpvumU{t?Rzzi{55O1W^9efDY@t|}+)^O{HR_u= zOs%RUo_s5rlAkRWJlGq0h!_zlVN!SHHLdX=fD>mzlMX>nlBpnA_oCjO!%Mx>H{hzc z->-?Wzq1S`&Q3c;Ew4hhNKmN&y`VNrek>E~|7Qf>fh~t6 zJv_s|vIO4<@Bor(*Dh4~x%>HRvl8>s58VI@I5@dYNhnE#&c8bh4t91?I3?kg$YyJ! zftVJLOhdXmD@#yuwKh|YsJJRJzg9w2BX2lfqrDQPgVLtp66l7?X^A2wp6D&7$XQ@k zaw`EsI<66u%C-3S{Cw*&4cE+xW zHJyoL=rGrBE;yYHkZEUC1xs-{eW>k>87*hb8^iUEg86z^D+gF&ef|yZxSf=f%XGqV zL}1}-{kD~>PD=Qg@tG2RgG@JJxKK|mQA5Dqjsh}^@%>i6J)%-S5BY?lqhrK40x=zZ zOXd4iAi-krYXGwTg^f^kexj#;6On!j2j|nW3Xl+=Xu3{+xWH#96SyJBWV>}`;>Z-Rr z|F(*5Brr_`s)<*i^`obBtduUz*0tCLTEa6!o&`=vg)>&wXb}|<5m8vyCLT3bDiDq$ zO?#fMqfn^ZIL<}dH)~a8I2wA$#bevUaFI-R*14w_`fW zo&3AKqFHW;<+P^1$hQgh&|$@*HN~P>2vH^N!!Ku}DVT+<;>Wb&C)8R2Tw&`M7&)}% z%9*iAHQ5pu5}D9WnxHuqNM}lLET?k|r?X!HOx6l^(Lf1kG`Fy5#t3bkv#~r(Bt0CD zX|f2k09z>GMFv82~vDVSm&>C+k%;uME4`}MT7)9(W@na1B=6YlmpnoM#C8o`>;gwC>= zH&R$gdBhDU1sGlzuJxgiC1X0t zwB3A5TdB2%^ilWoeryC3@ez$Fi6d+2Dk??wRJ7-_=LT8pc(Jx+Ray9{1d=Y`UkEx$ zG!+eh5Fh~ze>gHWL$$YCG#DRjVAciI$nwRS4irlPWy6|AvDzJBbKXLNAqwQ2G9f6a zV%9!eZ()}Vjc5`fjBXgeiW%0zn+MbI2jJr@lb!+ApQS>3Z1f8W8@I^Z8&xW{>`#CN z?;O7PZTd2wqb@;0mPBPU><^s#dl9?xix&>w4HPVOTxj9?RKlHm>C}moi z_4cYZoWKW7 zH~5Vfc`x2H?U~xH4tr!lB!zP=Y~e9d2FOGOvDy=ND@}kjm>Ai_T4?eCswr218x2T7 zp~YNZ`t_;dExv_~D(5*O1Fd76#a`d02L+fj69GK>c!9$)C5f6*i>6e7i%nAxdUSdZ zan1Q>Q|GRh8p3zFxi@r1<-*|@8n~ySR9as;jMq?Or6JU+JSAvLr+9Di?HQ3u7h_2q z^ccTor2Uq?i&2`+if121w>?nM+!VRf3BF zNDB!=sTnv5VdQ4|1(9e@WbPIA(QdHTfhhG6_EDR*yf*{%@21BBW|g3EM#kQL9dZgQ zVxe)q+0LN-8;BDFwb~WOxsa$;1q86nOJ0dLcE#G;b0JF-6536Us!f(>sU*=e&$8;> zgwrm7t}lJAu1^rOUqo&b6Qn4(dTMbC2^kDFnPlgByldNKU=Jt0Q06P_me@yggzeqI znD7$TBCuNvBA)>Q$u;3M&N50!Fjgd#CH62dE>D5ktUamEXaeF{4;_LP-O3$W|MS37 zdpYJZH#|6`d(DBT5fQm-i8iCn)aum7{ope~lZnN#b{!hBNHO%HJ?zpONYfltJ$J0Z z9~Qo6&d3cH3E-PYObPcM@Sp^?Bo8B!oxAqmCr749#aLD#83Q5#S=P6%IMbtK#t=h2 zGtjR}1j8a1@XH389&k9bk46l{fe}%xK&u9G(*!3-8a>8u&h!Ok-0fCO6H(I9&@rZG@^(~N+r7UKXd9QdsSJi#>zy2FMzdYNp!oYuZEm);lv-(PI;!*Wm z+n4H0U*7R@BZ^zu!0PG8Gyx~`&0r2a_r8dX-F;xJxn@pA_{yR8&@(8UQSoHK%GX+P zY1AD&<<;-3Si7u`=iO@>(3<&~hNEF%e>^YMZjGC2_e=SyF22dp&PLhV*R^`(qefpz zS>#>nC|@bxvQ8k{T~S}@I66NycmI0mXo{1GzCYr;^$J~rgQL+wV4T|H0rs9MBvw?b zC}u+z2^i1NyFjv#a~iJ}d%&1Pm2**RRGi{#OM{L}tUQX-sf}ved`egd{|(*vz{PS0qzY2^x^^+YY=#ku~NgHa17Gb-hcQ@Z`dX3tZKochqVtX-+h5l#cMUS{bn z8mkrZ)x4MqEP8Tk255Yk-6}C6EgVj1ofc|1*9PmwZ6>y1pI%AEh}cb{^wE4{D*=fo zm?pW#E+m$jR!ZX7dJHRg!7&eoIsfWv8KtX4%x;!kCF~~YmPc}CIC;ZRiidpOA*DXo z1C9S^cc9vV_4EJ7S>*N9w$GT-yh&fo5iHjD%@ zo=$NB@~3g%w%a^hY!E3+A}6mF?G8fXIJd|=>!J7MwqOp8e9Jg8lw;$of%UA+5n!#U z4L(&U(9j)Pi$c+?Y0jaXu${M+f3Ruln`XTOLW#F@mf{f98{?F0{8QEHZ-nY} zHX{+mQlGkmvCZztR_Yrg`J7#(WZ*di+*L(Zvta9LuO38}BSObNP7 z=q(Dl;-I%FC&GFu&#-J9$`NPDFKo0nPnltUW%L6{g!BZkB!U}>DOTIG*$skUTJz;RxkztLRX(Ci;_NG-7^}b3!I?u zE-r>BjH#M0En{fse7zwEVo#hE7SZ`U2@&ke+(}F<5i}y)p(Z~R0N<)>;u)h1Dpgym zsqdsrkD%)+*I6bH+4(Yu14g_z%(q4bC>+*?G5BkFdUnr5(EIjmc%*=NUjXI}o1mCn zlh{B(lZb{&qXOZ^UP}|?n%G4gvk6Fs)w|^NocJ^uvu?pHcZd@jcDGRXHI_J5f1Gg6 z;O_p9n8Sr$s00^#N7+REalvt@FZjl6@Mh{O^d}=b#!1Q;!tvf z#stfZ8|t32ERM`EguB$1au(^U>WC!Ql(S@JPkXO-R~@T$G*cqJp4n+OAt;52^J?RM zN)z;!e)G&N`y%k=UcbvGL{(m-62>tN)2yWmQVBL#R6#13T&jW`Xn#^4=x^6hNNP?% z#)!;PIWJvca|T#_f@BT5Q2#`g_fPz_QD==li&qXyeX5VeKK<*Bt@nF#;K z(?ucXjo~BUw)iu%gL(_NeAC&e%?_SnHi~J8-V(`aD9|w$(-FfwLayhT{^Z{XFzdSl zuHC?$q@@|49;0WNw^vB)!Jv^6#1_h9{G1LEjv}=iXaNi+=t$#@CKEe=OEn7y`lh*+ zWR^0HIgLF_IgVq5rTQd+fWQyP+K`-R=pX2scSBXMW~<0W0JyfJWu5%!&swz%vm51V z)voG(_n_~|)Nk=^*-^C>a|6lQN)&dk6-Tztd)j9JJr!wm^+8VLGh1jeyL+?Jo?nG$ z9OH@DEIdlfZJhBjC*)V7m3s<-*~j4GT#C7*u)7#>6X!EX-5CK$!O&PP>%V4vsV%o^ zjt~{gt>fVorQgT2evjNn;bM=oi5fb17XLGX@C0HM=0zMgJ;! z**#z2W!I3tq5`tJRaHtF(ctn}lZgT%cql5k!HLu-sM0T2->yk$+gZ~^0|e|)r4 z6@!g%#IA|%MRAoZ(f68-Kcq3}n&d_>Vv|eZip=$qX?-$;CthL&_}{*4NUPA`j9S%( z{g{Z0@#;-$O#+R2tX88pw8iVE&v(PCc9IIN$b4sjy84H9?(LSo?-sxBI`kd7Y;MgF z=uNypu=MFa54{|4i%{d`id)+JhEbDuZSmv1DIlp>a<``BZa3#Z`Z#{jf<>5v`^|C) z6AAdC8AK_;jOQ5kFTp9Sk41Y%kx%X>_(WUueo2PmR>0-ypguf7IaX(GixmU3+hWC- zz@?j8EtjVczEUnv|J4@9<>@L5L(kzR7R3Tge$jPcvgou9qGR21Z2BGWQR7j~j(BoGzD`X_ zX_IV%A$@Zt-$tD!mtY=KQn>hQ;)%lQD|ZL7zZv&;Oh_N(H&}7Xmk6#*nA`pU^^^%Y zKtjYc?NQcgZ~ne`bFSD$X_|m5#G*V6%bOD<%(#D6snW2uCHk7+`9TKspvI%@#cJ~0;u}(T+|yeWYsli9fX(_fs93` ze8t)}kYYLQx!8PO7#SZ!qd6Kgo6ri(IH1*fO`uPo)TDp@{FhIk)bG!qVIP4A9NXoE zqiaAELUh4gnp7~o++eP6X<9?d0Z)xHjBSYN2)GsCZ) zFBjx1j>&}Sqg%LDW;rE}qJgeeTyHWK0S?tVv4OIl=wh$I$it41<9>0#r-rBMCZ+9H;G?K=*(isdixYT@7}qU%WzNnI(eUi_hr^2#^!>@-;fqIZuxFS~Kv>99YjAT+3n+1%aR^?N zrArs6G$~HABq1as(Uux1m6{Zdt-i&W0@)QC@q=R@(#s|JgJ#-wo37yQ;0Era9wVh?}gb|;i{ znw0J{?(}vK0H;PA(a!dH?68c+GN1_>vPi8{4J(djRG4cQ?!Kc7*{A;)o)6tlt?^;x zW_C?DSF_}@%-aaWhGRL35@ejkCMb>qJ9fS(0*P!Cz|1-yC?h=O&06XLF}ak-{$sD> z%Dp!L=>!3-O+k5pL`YUyxyPo%eB-#+!6g%s%{pM z|MH%7%h70;M^@c#e* z@Bb&%Sg;Pj259b~bE3KKPab&hjoxj#i&&UBIWIq{PhEw;D(bz6TpRf)r2!{n!buVm z^=tddOivF@CcThx!gLhr>z$sBxClNercaYs8=R?$#56V(m=DxiFjhtgvlmuV_1+wc z(quve_%8j?FrumRtb~`&lP7uNCCkG^r;v-Om42^1Db+R&JBUjXRHMU}67HO_OlrR3 zD~Z+_AooHv9`t$op&K%S6~bb(gt=;I;01BWsJ9d#0S%lxf`(=Fs0Hn%kUM67f3Kzy z$d^>gCX#0}Ue+)qTS9+TO*e}SwdRwMMe3hx0-k3nXT~E};4q&`99T8->4ohbib z^l?5%E<6AByZ09-=RJ8VH`PbK-|xTJ--rME{eJoX{@%gvpLX_N?(Q7)`@1i9{?y;u zKiKX63H3Jxz@jHp;^&|GckZh^xIf6_)+R`rH#XXL?i*?(?|%#HaJF-XTrzmnJV6kPL9#6e1vSn{c8*z#zR8kz%UzMoP`GE>5ky2(08B`I1>a3HY-M)QD8!xQhhZsrZeiI%~FA$j{hS3hbxWN33p;y=N6@6|){}Z~s|XGw|R)4*LDB*Xa5{Yhzs(mAd@&a~EfFDt_(` z(5Iiff3|<9m+DXb>htH%U5D_JgJjQhG(=Bx#18=R%jyWimlo3Af#^3hda+NE@R|Dy zc_Y?TAE52$o!q*oZ4p++7WN`{5@8;p??^neYH;WIw!b2a)2z#A1miR<8Sb@3@zW<{ zcZ|wX?B%bxebQ{*6HfqCwOS;HUftmXtu$BqOhF&p8y7h)-6($h7M zZCqpHTUlM>+ugMqAhF0fMz^|vN*pyGksZQ^jK{UZShPeIg5Rd12exxUZANmhJUNw7 zZ9nhWk!d&fJYreV`dYV0Ora01P%Sid6<{AVP7uC)9) zp50vrTq6Iy*gtq#lK)=p?d?9we-H8Cl>T5@9UtMar#3>y>96`?7n0HLX(Ij678$i3kJ+VCqOu*ko6Ld z1mGvRl_b$2^fhSu=B17&p-Y9CkZfjO!ny@ZyXYWvP58(Z>pt%mdO$yQyZ7DNgj&;`ae)MvgL0EMFxEy?o0ubwZJY15=`9=0EsxDw|I#DPP*6vXp`bc9eT#vc zJ59Z1Ae!}KidP_YH}$HoLYBzl2+CjVFqQ%9S&13}^m_5IV}en6e|jISpRE74_t~CK z_W;`W#(V5j3A zG{tw7-u=%80;A!SIucXN3j-;<@CI!nPvuxEylBL=U&`;M?tMdVYC|+MwBXZ12(nb4 zU%Cd|i&CFi>XB&SMWvwsXJh9s#GK`*g%@6%I`ESJr%&Df!gW6yJ2esbO-z2MQ+VUI z3^Knrpu&qvL7NYw`lb<>m6@dOyO!KauiLVukTD+7#23G+tV#RWE^W)+@NV3JjCiA& z$0{2=H44{aFmXzq#8PM-n%zQXm#emKopW0CGRq`fyu2Z!DPva!FKIo2IHu8pB8>wF zp@LvZKnk!svUXjsLft4nS3y?tv0h;;CL;<#)bvK1>s}47Yi7L-%MOB|b3d{^3)3KX z@7lcRuVe}%eR)Hx6?#lDkOFR%Fra9MTG7&$1yvfzESYCC($cquzlhyT5QAT{A$@6e zZR5{k{ol~w9nAns^#9!#JNqU5|K*E={YU-(A)fVl!Z(^W7O@6JK6l^+EGB1UtlG8Q zU;&IBgsN<--Y_9DNF4xtM%Otncr#Y3nO!Wvg#w@;gN4|Qs>VFnyF2@BfodZ(1zKwQ zT_D}?kwER{$vQ|c4{1f5-~YDQVqQwSSH0>|_;^%k z^1u2ftfo%YqnZS7W4l-RciUVWr7LWCRmuL2XK_>4C3Bj^l6uTdHNstkkV zR671I9uKRz`1HvQ1uFE)E+jopQYI)QwEX;eu)Ms)6CazjoYJDwLh3&H^{k3`q*cU$ zX8_7KL3jVsVre$RNtBljn$Z)WAS%oa9V7Bj2U>$D zm>_F@g+SY41Hggzp}Y2k=>}WRmnp8Nt6Kog+I=n3HV7mwhP`YJZMj|@*kEJ62biJV zRRJzks)N?p95tNx0JWdfVO8Mk>egbsAY$DI>iw**-&5Hh{pE^v;BOw@yD`lYax2nv zg{d_asW|=EG%6;ke9y!!H39{^E%LL#Mm9C>RXQa3A||KMEqvDN_N*aXYWa_Ye&1u_ zdiSbw*W%Z@K_iI6t04I9;$nF2zUbqQx8OP8BVI#0VoZ9CKx)sS?tIFG z+*aSWE43nWy{J+|uB&xY&ca2N)c0yFOT-N|uQA__=_n7iTPep`iYF#D!#6adTwmnE zabs7(gr}joQ(f1mj70#Ko3@))Qu)qPahKPB~A-fwd|Y z2Nd9ID0-RuEVhopE~x4;+FCZdpsLSq8=38b`c0g-H7PG-gbO;Zr)>l=g9hjr7(CiWD^S`PVF0A_I`zoCC-Op@g=F28hvW(VGK9PLTRk9*h%N^POl zh^G)=@nNW^0QKtRQ>gCn{?~QsXLUp`q@dNCtJ2Wou~c3ZZspw4S?$f4)&tw@bM19SoBh(gq#B}H zS1TC9tHj%)88_4WIUr_At&LoZ2;L@T<9Rv*%RDuEQt{BC32n}r5!6^J(xO2_`+RD{ zfnThIurf%BtRc9EnL+z|;W)~b{*^tR9v}ayJO9;8H88H}cRvDNeEz%l^58|q|EvFU z=kfgaA)eYzM8}qTi_=A(EhREphxf0!F2z7vd3w$=2Fo~Y3QJo6Zr3ttK=hsh7 z3nplh=xM+03*fxZEHl(E1I>>MY;;le8dkayu#Px^`y|gXhXyON@JoE6CD$XI1#x4LE*sNK?r_fqu@rB53~U#h)j)zLu=FJCWojU#?2M% zV=At|_kcw2SVV*yn=a+nP(;O55bJ^gc;hb|)51PBIT-W%7)w0Fa_Yc$aAS!BZD&~k zZmE?`0%&emowKn#Oe8%VYg3y8)O-&F8_NJEk_OlmSqO1Mv-be`VJ6u(I^1~$Xq-tF zm{{m-!1dbNB&6md-}`IAhn!tgwOP<)lBeu>Lb3kR~at9uyNTbj@r zjt{MlwP0K`T{Lj|*oxz7?&==Kb!JkL=AFD|+~XOQ(b?Rk-k^dp;{_(wW|Yf1-sD)b z!U41!l09Y)_4|cT7n`^T?rGAhK;Fj+2eoTmhtX}pMg7+9iPgVhA&z}6T449F`P!D{ z+t%&@SQ~BbToC4LedWc)8wap{A6Vg3E(WyJ%4YXl7{3<$e0flK`>sZ;5ibjp z=VBUZZhW&tFb$t)5TJFO#j1<%sOo$U8LPdqSm1>#4C4r&ThK9+98$P z^~|{14{1q1i-*KGdb--MB&LbXQ;a=(hMul+yyAup?F9Kj6pZmJQ|Y+S=|!=#B8)cwycdI}klLRslFAOEJ7nvS}l&tRe>7ZLcKck;IO^3!bxHW*+Y zZy4++fymRn|Xl=es$ZbkONuqdOgjq)x2~rjXH&c?7?c71;)m%ETmJn=IEvG`UwsRNz z?0s^?c*GKIn$DGST`tIjqy;PqLQ@nN_+piOaX$&f`r-jpTUf%uv4?hr)mCV^EHnL2}D~B&$K0O**MM4YRr<>@VC}zm-K!Q z`|BCeCu491;GKHdZIzqv`cPrX@kf1|8?__(a`ccz;=Y;uAqu(2VRO0tW4yQi`FR(!p<7Z0y!oHmSQ z)gd-_dOw`=(B@gzshG@l-et_wWoNe02JCU`TKsc444Xb+vv<%9(rY*S;yrph$?Z4$ zCH>sjkj@C)b(*&r6E{WI98_ITn;g|7!yG4)km$4+q~U0I=|+?nsz#Rx(`?~j7Im=6 zf#i8bj2%r8ya;hj_({p8nHLRQ@HAIAaM>pp3~G62n;e=B{(ESR4gOi3{uJb9jb(>) z)wb@zC*~cIH;h+ZUlRSkjdzP_VzWAz8gMcJw_B6G`*n;bo{FUl1ff?V7{_?BM4hT{ zcayN|9l%KZCUdWY+iVY3sgO3Y?*f?X+S@20nEmt^OMD8cUVZt@e$}2X)P7$~7j-S( zJIJTA8Hp&C+HdJ_ED5)wf)xgrjVhqF4ecitK=NiMvpD&5_0hKg?%ok}q_aURMS{s1 zvHBoQ2b(oT%-A)ts1nB+9Q4zeXxaIK)0twcqqiL`-7JLAufI{acI)8UZ4cM({loQLHX$jVlq?TLAcLtX)MB<9 z+upbx@MM{wc;7xZKd!(8K+V1kUl6k3^pot~HWs4;vrJ5sOv( zG?`f6?Ms0t=5XB#ys7%!>O9?V z@4nXfw{7e?r6qqCGf&&T??WMZi*Jj!KHQwl@NJ7LALVxLYfj#j1*{VO+sRvXE#4!< zuVXwBiy$7W0;@m_EpAld;e`B3a)s(OKkV=BJ;r}{h-X3ke@6xjqd)+K1e#{n ziQ2z*6bKun$0pbupq-e11E*mTd;ID1}|PsPw^p`dUe z9us-Sm@EZG&O!eE@|%-4Cl?>i-oL;2Pz;dlLL_^HwXE4sb@_{HE(vJ@RjnD9*#a>y zC{3?sW=4#+;LQxUQyP?GzDC9EK_yrfD z=ltE_@cg^?7Z)2xQ3I?^XsSYdH&n&+nz&3Ji;-0Vx&t_JIzNxddN3bYy$CA_?%aV6ACGuICQKn5! znZoEgwL|*@yMWdCXLB&zTD9 z@VtJag1XioI!^&wlrxoQ$)UIugbz@^p3^q(Zw)z+9z40vmp*^_($C`azl?4o0r;}> zzZWlFl=FWdym&nSdyuEJU|C8MF{NYav;M|18SQbFX+h@+*viFVdwW9VG#m9oHrsYZ zw;9glG)OtSoo|m~Hrk$H#h$lAmPk%V+k!?U#QLbY^91STiZFs2mTMuym|&+NiO4uX zRH7Ri$0!p7$tgh^pf1$w`Yiz)BPe7^qEk8|$)JYr;+kTFb?riC6?o%~nX>$d^bAVh zORANOy0cbK>a0io+L_WN(=4@^ItHQ2DK9`H?IEfpd`1&dmGf{u z1%{Y>H-d#CUq&0GJ{R`Kb(FHmkLy#+olnMua}wz*M0sGQ(@DbI>yuj&X23NH)`%NI zCsV22H@qfUWP7?GymDd)XsK!<_JMghxwZExM72bKuE-onxAF-gmMWEv@c}wbYCePI zrKZionYo#X{E;kWF`LZ4SN-M}brm~N60Vmix9X12W}9A8vbbX)Pw4jc=CT4*wDjhU zL6xDZQM3-b`fIvGEbpOef3B@lvYi9tiUp|wvD;mw2v$5QPRH+<9C9Lvml=Iomh#p4 zvVBaF)@&5hJWVU+lR|F++%FRWjv__yuLkS(rd%>geY zCwTVCIah=@Rx4oe*S?p`T@{tFfGzgbHj&}BjK#LG0jj@yA(xfXS7csa_=?O6g+s=! zC^38YtMikivy+RafnxsZQ#ao}2Hh6hOLwa~;VetLgPfOB*4^rIB3QZOtfdat}_5?1c8#2q#iLu%=~lhN{mUf0uUQFePY zK*@wAw?T-*sgK2S26_0t4Q0z2=<_xpht{G-pg?^q19Xjfz_UeZ?0M#8uV2Q13MX&{qFtQyAN*<-yME?a#l>Co}V% zJ|5fL|s z(~Z#Dzm)VfPYLRt;Ut_A9)OC~wXGFZSsS>@R34zN%=RMP;!u3AAk$N)?7yv&g(kF~gBb)5lMT=;!?Xfo+t{Z$ms!cKL~MRx^F;}3X8u*w2*7%Im-4XDuPhTmv?)+reFYjN|_ zWv%innm0fFlPiXXzPcjwE%X&Ay=d^N0)Pi-UKwhk&!2UE8(p`gyLcUzw#af1=6|Ou z=@!awi#C>pRSRR~SxgMW1uI`&GwOqd8%zmSi^FnSuxq$v!&X%5b}NmgUXtOwnG3s* zyPBu7G$u2WXyl%!B&1^+*0*=zc6$3*3rE3nVWpmu>AzXl@gLZKDu)V5HX9KR`%=U7 z$=DEvIib~fHfRf$q1!iM)D)Gm$d&W@qrflC!ycdYpPK#OFnJwsof5HKj2jGLHna&l zC={JHNeoN&|DD~JrThQ8FL!qPkNf{aJSCQ5CUj_~ehoR`o!7#=MjB`&ru7xSltt&u zPUXEbm~EFUZZR~Ps1@TkT=mq+4u(1E*JF2~HK>Bp08Ujf@vm5~)=tCF%8`;b*K!eQ z_uRZcCy#s1#-G*szr8Boj`#nm4gY^p=KnAD9`(P6dA>0J&zZ-U=KVP&k9_};@Bbh3 zwBi4in2X->Z(}4}%K!IE{{OrCFAfeK`Ts*a56=H<*we$a{u&@2xdECyWyAg>*Z)88 zX~X|lm-vg%GX8(?;-JL;_g);lc;x>N@jN*HuVI1r$p4$T?jMEQ*LrH)rHN3`AdRyL zP439TZI;f_ykVed$u*1sebQGj3YimoULRZDJ&coEDx^T4mqNX)H-8Mjuu&kfxLT{D zWtc99i~N0VXKnbu%M@siyjI-^mhk`ni~dfD{~zo>%Ks1Zd^!GKrmBZi1j;=x2CD5= z;kn=kDCJDDki`RZabz9lwR_Qj9Q5~oN4%iT`p>94v0h6CT;~7tqU`^(yTAW(=W+c% z#8cy{*u(>xe1x7t+e3ST)jMRqQrYS_#Ehd*Y9SVcn|an2hO_a|8D7Fs0QCbalIXP;?)z zFZTQMpK7!J-;mLiv8#Kt|LpDUR_s47AJ2au>-Z=%6%^bZ1Y;c zP9L2H+;r}TUGD{~MM+7W#cfJR*g#Yiq*xM=R zf9k*3f8_rU@%a2_q}F%NbN*spqTwt<=XuC!4~dq}Sw_;3%dEIVT~5Yaagr!r=&qS8P0f zqw~`4EDij$cxdQup`rW;P}O)sl}HCQo&Rp~8m$}aqmt8TK}MsXO1-EY6=PXWpN8}{ zP04NAWb@%fu_tK<{yuq)X`FFCkm(;QV1r4xdbg+z^^GhK-LOXR+qJ?GSoj`8KHOi( zhdLau9rvNGu`d+-!GiJ_0pgw`K-407{V))<&D|ju!~@BHb@D$a8x{YT$^QpC{oQi> z=NAVrALajtcxt#o%E_gk|D!1huL$q`!bT@0E>JCGXvSz0@U~<%y0d=4$!67yE%-IY zG$v7vs!{0fUrN&`A@V^LjY{8tcs-*rK?2CL*EA**5)F{#8Ch31sX^MJNQP>yu+W3U z4<0yWLT;V{_(>>97e%_dBC}ojAQ+%z{{Y>d(N`!QVV zXbx4scYZ*2~OK_+of^oP*#pC4wl$vzQFf znR58 z$B!5fKXib&j`6OeGN&~1iX#&r;jo7@Ic1#w3X@UUP|jFPmQYK;Rhc`)eq7OH zXW|qF2&XhhWMD`i2ua^ecJCu=`LV8&3d@9#Oo2=gua;8i&46O2f4mR|vs`7&T&xf4w^z~s zUq0UddzfcY!dAQEEf6v8yvg1{E>RV3sGOF=>l?7EakFb9ep>_Z!n6X*Qrot`RBckc ze@SGuP0rOaF_$TpFu5-5B|~db z`~EPK(=$`@%$DqKb#qGT4!YMnkn_)e9k}X{Ji5CDc?G>Bfk8&QpFe+HhtkavqtY1} zm%%7YqWB@b8y=Dnzcg$8Lp;s<|BNM6GX4Pj|L%T8{_pQT#{YPb$8cA-8fQdu8oE{a z))0YZ+(AjCH$*~{NiSraFac@*%N)tHvd~t+*^J03$wW}3zdJA|$1PUO7_tIrHT-Ex{~wg~|AQC(NBiG{Jc|^G`$;$1c<=w7 zVgpq3I~F&xyT%15WfQC|Rk-$#O4$Yd8r8G3hnbY7umSfISzwhZSv{&iX+r7>6=DXI z=fkV;rKY1HHr~BN&s$|OR*jrjnu?k-g|K+#nSk=H@Rw$l|B_GL{x2EF6S6V)zoqxT z`ui38|Nj1?|IdRwwY=@fIfpE=A$nx;fEGjxO@&Ga=r>>>hCS=gM+Q3ZMaUf;^+(UI z0xi8XWp&)L8Vzcl4@)T=n+S}fKmebMXPgQkA;G|GO4VLvPdU4$3UtB;NXHfS<0R|x z#WB120bG1eZd05H-vvr3g<*{8%(^Oe8=xo@L!UqE)TP>U$atK*Wf2*m)7gwf6ieND ziaDMU>D~L%Su5X<&qx~65R2w6{ehd(M=VRE>s{d&$HaVd%5!(GZ@-T@n|*`Bt1KO$ zZnxp4PqoX}qL|flEOd_0C6Kym-IlQrYT9^vH5NmKG|vt+bMKadP^i8R7&AKISmIIa z4L^U^+<&27wPW>bdFRPkyiW`HY!S-eHFsX9w{GVq-^3~0=hJ4*918zq<4P^Gkhq+; z<@(21Vx71AqMSj#v9+jBXIZ<$eATVkdS0`>54gQ6vRS)!t%tR()jldniS_6(@PA_? zYbdNtP+g$``ns8$Rh#^Ujowg5fBSV4lnPOAScqdP=gS!Ou~)V}1j%Afa7@Kj<8UMI z<5H$jXi4OEhVH&ka4iF_(9#`&<7CFJ$$5fPF=bL5XKIRH)0pV6pckBa zB$y>LoW8~UN|isFVw#*m^=Q#1*rxrp&`O2E;Th4}IqY+U7v{U>`vT-Pwb%71`6QXp zWYM)&n%QdoI%O=Jjwxf&3%NO{3kjEWOhYUQ`VEa$;hj0UR3(>2&wR*Qqcdiv2%AG^$Qyr3iDogZ8DxtapM2! z)1W<=DEw$91bx>_U-i;;3UB5usQ1!V z|A&jGp_cq}wb0jymeH1Hk%-DQS(d8$$gv(d)+5Jy;`<3{= zFJC_9e|(tdiLskbBzhW?1U-!zyUJ43T_mP-QP&eux~SXL>HYf8#|_rb?aTgp1W>s zeVt(S+S;3N%>nDmtJgaGwm8RwIKBk2vTcQ2bpQTMPzHAX^Cs~>U#YgI-zTItT(Md5I*pcINI713*tBvIop4b@j4w$NAPmI^5p`!{VC zAbLvv>59P63Xs@<&8T~3|2jH576@~K;A(C%>7gOG`5+^sKtT79aZW_a;F^-Eg2E~0 z(zqJgqUxKRQlUTgVE0-&Jpad+-m*9PERz3Hky;t>KIOmu!9nT#Z@1sydA$GmAkTfs zf1eh_lz-xd^LyIJzk1(cfx5+*^V^kZ^WA5z#WAKa>RwEVxj&9V4Ihda5zv{-7*S~k z9S%>OY0EJdbF~5u&xZoh#A6wjpQN0HgeYFq>lV30^WR^3x+{-c|Gg=RXLOP;kNqjGlkL1AZF)mv8WYiZ-V--z=Xr00uR70ra+Y?U|4-)$`T=vwGJ#HyPei9@ z(jattG$MFgm*ec0KcZyd*8kbb;qlv(-YnXDAItoI_A2*(cK2TFKCb_Vc%I~mm5$Wr z*6I8gdj9-$rWQC(IMMTvQDJM8W zIOI$SgiV+Q#Ks8R?FXICPA|u*xz!m2=t!~kkR_6{I3|4C9J`^IO=yVhxF%Fivk`>w zbbKLqkATKHyI%X&iHOp>4;$-wQDG&uu_JcfbuV>Bm!vpFu%ltc$P>yQ*=B_v7|~m2id`c`spzw zUqIJ8y`8(2#MaG8_E?_EoLe$c100Z94j6**Szo2v02Idt`)Wq{?h53OUxxKilp*+ z3;i@?5whAE8k#IiIU}y5><@GQZ2Otk2LYw}x__kinG%K$ zho`+x=TNa)PDB>VE%f}k(f_hVLwo)lJ!Kpw0F5~jQ@4LAVyI%m&c(AWlnKJMvCE|{ zluXIOW5#C)D;fyWSZ%5%CAgkhr=G%^_~^9mk6_u841EMk+ef8+Q<+m#%E`5oZR5Es zD0xOcdfVyX`SZ?yq0=#%v&?lmXBl^DcHQJ!JsI$;&;+XVHN^;{k80PnO?^a9$+eTO}1ajE1AXoIEh<_C07g28h+{+HkPmZsKFraHB9g{z zP9jC8R4Rg);&_~|1jisi@1p`<+KUku1hsK^235CQfJR}9S0&WsmlyP*jkI`|745<` zZa+g}%Ca~@Bcc{jXcL5k>d8hWJt8BPqTMLLPlovv%qz z7+R5d)a!s7<t>J=%XCllum`mJ*mq z9R#XJS6hkra!O``#Meqcb2>VS44?NA=LVab->qNjma$74 zS?5uEebinbwb#YkYg$#WtbhpGm8VR#&}$zR+dCYpC4ShKD;U>RY`eF3j&+L%_}!Zt{L$5jB>8jg22|K zET|1ZRz${G9xqLAJfwQ0ryJXq zxZdf#?CsVJ?*dQmWn32qf;$dKpKjl6Zp{h#YEx^@=vTsksdFC_Yw&Q#dA;+XHZ-dl zz1xgtbj8`cJY8+jm#6nKiy6J^46Z$p4b2=a-sZX6G*-MvR-4p{o6Aa=snouY2`{7T zjToxw9Hg6n&0XLQk>keNaOIMRz2H4G(lfL@=se?p%u&>bY0P!Yium8-HMV?ftnthrQ+ZG2DV{V=97!m0$-@AZ582d%l&eUANZR1yl> z)A2UeZr@9hM;{oVbYe*a|)qWbc<*#v1N zEF!w7iRq5lCo$Dlpnb>#Zd+?lZ0}e^EZ7d12SIIp&l@MeI$T!?aksa#+ls6GKJm2) zqU1!-U+=){O#Swxccv>m2=W}>be9{aGK;)A3B4s{eQ|Vbf{3hJi@XCNd2O^Ort`eg zLt@bHcH>0lBeP0aFMIvo?kaod?*>JiAheiXlY|H{aPybf^m<`w?B9y{R6pp1nbAjIeFe zm0k@U#);Ea?s})G77hz-K_4#REG(!(Zx&xDd3f!=oYBf0rnAG@- z8~_@ZqcD;|6Ln^yR&-GHkV!2Cj$8ma&g7INl7<-23I0|!#Mr=-{K;(x{SXUr6D@>4 zRYe$&YQ``$pVkGv)O0;%I)kAp@WHIX0#$-{N0ls(G9lTF{z~e6`b14Iu>4My*-6Hf z3yCD15yJr(w5?qZ_3CH*3ej=FDRYX!ojJdL5}scUc% zb*r8CDjSiQ$TP;|G3A9hshN9I8ga%XiYSNtMl0?pZ8q5NO+N}ObZq-sx}!GPV|{y~ z37mN3vb$**Xd;UQxd%TX5zUVN6Whkap{GB0_kQj^Gl*Jf zapZpgcS4e9D|<*hc{Z;5L6vVr+Z?ux%Kea-GWzoUV96@uo5PT&KRzUuJcaLmFy(8M zo57ZWz<%zHyy(3?7&?$C@;(%Ca*{+TqgJ|*Oi3F`IZ>lDcYGw{q=%lqPxYpNe(t_| zeg1QI3;o-Vjv>qKO zFNwUOMFhQ5vUN2Qh7q%|5GRDxkly5rQg6*FmQO73vjm@^zgc??$F*D3ff4m6R99b91bQuz!ip$ou)7GREDN zG|-gtduP9}k-i?pv!wU+>e$SMqgq*T5n3&HZ}Dx;hYSksl16XwEuCdEl$R(X%YL_w z8TJFxutABw{im5pesN<&8Iz#K?Ut&Ymp;F&q_bt8GIe2VzLTy}&6GQd4?y`=kPO zx34kZj_D}BYuR0A{IzOsP225p@rH#srgGkhk3xZZoR}~gx?B$(mZLGi<-|fENVThf zIeEeCL8gj{h0To7M{QC-QCM%?DT^F&>6^iM-E|O4lI(x8_wCJX+(_cTzw;?jtom)N zJ&}>^WRr4Tu1c0)+Vz8F$?@H-wl2^NNFp8rv%riV&gQ#cp}X;#89pS@+P$jyAB!ZO zjYgy2y@ZdtPRdG;*~laQ$bWGzY%>OERpXgb0s2X`Vn@QC<0?*2U ziSf0#5EXOHnQK4JI^;)!4MIjJ>be2(31gaEx2+ozkB^KCqc-K+i14nro`NPtl%{-fS3%D(}xEKx8XZ8W}(9$JUrOMAJ9hL zNF|rNI`qh}9(2^2h34x)cZ|1i>3X%x1moao^-y8rst}??O2~_*3LuG3x;fG+rRM1@R3KwBwaoi zhT}3l*6+LDbR%b=hu4r+NpKU`i6ls;W73MYDRv&PeRt2Ew;OH2ob~iW9p=nGe=EeY zk#CnJ#KpJG0oEsyK`y>bn5YamFY+9yK2)BvrY?0UXV;i>6X$t1qjlMz*-VP6^k%y> z%hn324qB!=qj#btd(_45?I7>xJZT(@kS=`a9HQ4WG|x85-l8>j)!8I{Q|O$HZ1UNS zaW(?{wpPv+5{&6jn5Sm?(~%{S(ui=HAbhLH?sXXQ6;rs^nO9c(tO}0V=D6Q|W;K(* zZr9pcNHt3dkNEI5+|TDym5hgEZ6M_)tD61$$aCJoA0osqZGRDxDAS)-1AF5F)$3av^y?XaCoj_EwW zhzFF@U*u#VftJ#Dt8d`J!PzM207UxJ!P#h^)f!ENiArGCoY>=yoY;)ZN|aR3?eujD z*%$CrP=m@Ppy_LQF?0cLQ)fulJ0FQC31J$QP8q5TBOuLCJpN8Eb>a0Sr ztlXkUv%6kj!U&(~kBVXg1BL`I&u^CG2Szl51i=TG9T+m-1wiGht-3XHkTh4!c;6S> zt?q4<0WZ4GzFQdZA#dO9Z%MN&Dtm)*JOMW;LIB zIm#rdB>}_T0lqv_rh}a#+@cAvY$rieUA!m~aJ)~l>dlPmz zgNl8`LsGK8xGcv7K|Vrn5edkZmM!5(TWDD(DS1!HSC_g~4utot=0I-vB$z7RsUvMl ztn77+zVK$9d81ufja+})&g|F>3R z8^e-ocLT%HsApJm(&YQZdPFyubeUiT4=&q$DR4q=`z9zq$b>qTT7B*KQ73kz#^4$| z1Fw26SVKw<-k-pY(MYdt4G=ei{M5-({&S;iUFrGtBu_&5Su645zr$oIaf@*W{vSX4 z$vT)odI=~N2+lU75c>?vd3wDc#B6tp{}h~fChezfZ~{CT?r3a8UxGUt8v#=HN{!&* zc)qNgYlnm2N zURyMT>+c%UPh)Avw$XL%ogt{zCBL>~Xxu&H%~P$n`8aO)4dp1O5P}j(mvtA{vzfW= z2RuG~FCTeO63Mf8`)xS!?C^_YU7(aK#p)s{7@jVwbcs6reB&WTh~8v8P5@ z+ZvJ9lfW3yP|UBjAcau^^41#@-G$Q3A2Tc9v_K67=fJK- zvyTb*xsAmye1fzLJ$|0BkB9Hy9>0D0ggtx5-o86!N3RawzI@J3Umc&Yljouh|d3xP_d3l0S(yrnPEC@u6Q1OX<7KX<~sVc;qTW%*Hsy4+1beJIXWvv z<3Ckd00l$p%s2@HK9jSVfUN?>GordCq0Aqm_0?HQQE{kPRJpx-y^@C%ZlZ+JcVr8S zU*+E5flomp*kow$X;8o|`$@WoJubO#Jvl%vm*+KrSmv(7Gr^nI2zCj2f=g{aP1w_x z$R66d+z+4@cY=ak)*R(?_bKj??f_v!tocL6#hoMfCXcpw0LVq44V!GNTi`b-V950C zZL_z)@*rrfM)FwZDf;@O2az|?uCb0M#@lqdy#JRpm~T1>n)kgxhga~h%AMWfO~ocG zZL@~eqmeD$De7EcXRp3B;{19*VTopSLrFY&Rk2GW8<7^dfqGD0p#tznI|u^yg6bgV z;eNGo12i($Lp~c}%ke_+a(s1lHId8t*$C@%KM0}>pf#w)=txkWEA zDat)4yanPs?H{jT6CIACXByOiyb$YiPBeN;Kel_-6CiJg3{W}MrG>;M)3&PmvgHZ# zfz%kZ2beI$HD4`mVjIZVffcZZ*ymc8Hgaa&9Mm~SX|Z~C49uLcqXk!U)VDZr%HEWY zGxY2w90vz;1!(sAEAiHfooX87%*prT+6XIDbd*PNF?<9QO;>E}cipHBqq3ot47*S^55k-FAmG%1GIH`y#dohUKuWrFFJhg~5`l$Au>jkF;S60tL z_LloMDjvDMZH>3#rBDKD{`nBZ)wV?H=dV%d$+E6@F(ijNT?tyx!!*G+1W~`kR1ml1 z1guIlyOhjt2-no(3;BcXL7NBB5_j>1!0VwI0SuPdo?Ff@`uu)j8QGrzB&^Os&g@&T zXVJ%j>UwxT_*-yjNVyZgUw|`8`5C7cDhj5I8scit5GsS|dC;win763f&;lKp@&olV z`Y=AfQXML$c@0DQ{DktAJLdE@iIZtccS878l6{^%-QSK)lKmzZ)7*R44eI8g`#`HB z5FtP1&PC}+%*iMTrV?~BfgZPdX4i}6Hvr{(;@!4`rEh%$U~b_GUFu6!X)Nf;hd{~a zT&n2mV;kPIzyoui2MwX>8bifH&kdc8P>*spV%o5?QL8>FeW`X3yKrMq=y}TxSB((m zabEA_X!;=q_{-3)UyH;yT^Ga$T!LVPc;S2k8Hg`6m`aL5Bi>S0@p!fkYDeKzVV zjywfKn8@WmYA>W}glmo)G>CDqz5@r*Zx7;1-YG$G zdZJmmaJJ;vObL7#&SRD72=T7YJ9`9~YLe*tq-FC;pYtk6v%ZU*D^RGQmK7~JGm@f3RkE{D|9-zm z1a?$Nh0|atD#uw5NhZskm5`d1`$+2sq3aK!zi5q~lo0`ft)UZE4e}l!lA=r#m)f}V zzYpF2s+h-byDqDbHqh8g&%q}qrKhj;oW(D5uNe1R<$j~*Nh&PBjzsjjrYh@BCY25N zhgW(I)S=6gtx6_wtY&(YW-J;_xst_bpN(GdhF9*7=f-H`{`km^a{oi8eKvX~&fB^B zvbXZ+YE@ zqkG*Eda^qy$QHa32IGaxud*D6N!h_)r^hRSRV$6s0eCYekxd!wB*Q4{SX4n~NrtuRp)u zVojrM(_VJZF`Ob+gk5)r+SCiK4!!F)hKSIay@TIGiEJAQMO)>?-Rz>RnD(Rl$2n-4 z3vG^bL;j@`6ChRrU;g^=3S6qGaalRdF^qpzUf$Nb6!C(*? zG9ILYh<+}PT6Y}i?LOm<$BS;beg6z{T<~04RnZOd#sG&~P=p;5N29&8V?l2W*b%^s zDCd*fx^&OB=atD9qU(lpQ&i|Bp1;xP#iCpqLjSBTqPg|d6;-ZOoUcwyb5lZt%Rhhqv#@&ux~kBUlDu)z!F^&dL)E= zF*9wJAb)wccpz_xS~4tb5b`13pUm_gUheQ9iIC6wO->LZ3{u)vV+W^o+eaJ)JUa z<~HHa#SOyTDC|U-3vkux_*AI;RqvAw2Q(PHpwVekGH#(mjGFT)3?J!bZG^Q_t2d%q=;V@;LX)jME^Ocr$r4>8!!2RB9lQ+H=Wn;$the-f z%W-$B!T1afz|xGr_4eGiF*~6SG{;8pGI0jXJpo%4Z9C-ncdN4wsk>qZzzviETo6}+ zz`H-*1O|Cz0ft#8IU70vsVM*(47UkP?q~mimPfj(MB%>h^L(&;F5Za7$ijZr@j{BN z6W2HkNh(8!o9S)xqR+b7?AGndVxJ)abM8S@~MDQj$e^F1QX`;?(U zCM+MRn7Yb_X?tGD!o!F?<92bbxhYwgd5J%znYZ`w3F$4DrjO1Oh(EZ;#NE~xD+m$A z_~O`os*?rA^C{zH>4?wG+0lX57>ekuL%EBGjvYs_IpS7svb_l{6+SU<*X}#KnT~CE zM|*lSxTiIvM)P*!!Eg`6?ue-akg|4GjyS+N?t4?Gd1UbRKb?SLoM35U^S!$mY)TCAQgKfpY8>2I-g}{Kz(F|HE85?18^Cd%n>Z0up(WCw}B(=Hsp?c{-WS@o%u6%;iuK@g;nLbj#a1t%uqk!q70t=t`E=O;0FNwk< zLiwgvF#S0s`{q8|b50JvQ%Rtbi2mJQTqkmQh4BP0xNTl=S!q;ec){o6fBJX>P)qq1 zn+)fttx=F5N6%$Jep$%QmkczDZeZ`A_4ig5pJF8%Fr&6+1)|(>|Ftky+D52C_yo;9 zpuF$HePcmB&AUFFjd}D{FXgjm+Wb0tTh1C}8>iR23`Hw*NUYkp5k zd&r>}gNC}vT44wuyhCO{eIYSXlWh!ghBoI<(gYM}J&=uMI27p*Ujn9Hsq?4&VP%-jdvqUz4`z*fYG30Dwds${^^@`-YGEENrIn6b#Jxl z3>Cbs6VV~5jYCMW{_1v0TiqBsgLEjb!qctSv&pR8A^0I;%O}*Dpx}E;eMFXhIA+yC zkK@%ib_2lVg+RL4m`0KL9c|_W?og_H6EuI(=dYz5$`Aei=AdHForFvYSpMGXM)<6+ zkYUA80tDb4iTCj1*WB=>XoPY2{Tv6*!y_rbv2!XTIcDu&g)tEa3MjKbL z^7OmQ?IZcKTfno!HbBsKlJF6AXH-_0HBRbGD<#syUh;-VOt(+iNL?(&zU2+~-sm^P z&H?<~9z)Z7k9Wh+Jb~lAV`!F+^1dkR5D+u`9K_D;tf*H8fV8NxYpJveL2prKJ4i(uM zO4xO>;0PvW5f5qijPdsvTkPmIvY! zpC6I)(!k+7rzY&=)#3QNhmSHxr!FRYQ`V{@8IA>|x{CQwkm8xDa3t06ZMa&}`Wj{y zqDZBhSHdRYpvO(D;!)`3QYb2OY<;-~>OUJkdvFyNSG6|H*opRI#JRK4_Q#q6&%rK( z^Zg#R+ujN6?)17Ix`ofW`@hBc4j&~|3(l)%bhR9rHL}s{LKuH5@h%OI9c=Y5$v^>Y ztwiFb7ay7Kao;a)9^wO+4_jm@XnOc~Hfrlia}cSq*jop$ODF<&AvybSoTU%UDzzI_Tl%zgb6AkoK;}x4q03SOx<#YDw9+~lv&QNJTat$R~i{NA&`o004LIE5Zcf8nGZ1o^-q7Sx zy3IZPFWtiP68?~l78$CH2dFL9MbquqPDZXoBACHZg zORXk+$v8axlN17QFGjb)!_J|7VFq+N zhx40?NHM>0Fr~pnyz)g*dT!?H6fUVMkizFt6G-kM_#r9@H|qqqcb(sjwvbj$%0gQ9 zsIN&(a+diX>B&hoHxBova?hJDXoYhLV}Q|*h3~e z4}%k7E@UClStaRDIoG|!y48$#kO({!7TR{IfsL+YJ&}4eK<-{?+oXj){Gy;R5Y>b? zlk^%bs0V!2vn50i>_K?Gik*j+Uh`(rS^76atM=GS{g~?)=`AmU3r~^(k)2<&nReIG z^C`0yQa{8Y*ss63-Tn64zy12F`~2H)lNAJH^}dg3yeV#F)h-kMFr*J~bRCS-ZkHH` zhqYFFnQ7cwfnD*60Y7v`6NU#ws_^`Z7Y+V7HDV^Oh&*hOD}UWO(R;*=oqWa#MmGQ) zavdq`EZ(t6D<=(tE&}d7SH(h@@zm(6>meIBbd3N@(_&@-qww=pYj34+LKSlT=oh5wP+h7vq;IW%_>FI}~8KVwe{4vnNEh*O^CCb*k zjvggPrl`vR@79aUpr#Cp^r={EF*`NTI7=hct$RGW}|M8FRFa0y6^NYvE!nSe88SdlpO;4uVJZzh} zkXo0_ilT)`C-8-k!m#A5I>9 z2j?KTsiYHB-G`v2gbd1jiC-%(m(r4}K&Sxc(_{j3erHp-??DCEIa;bUAV+@H?$QGmEj}qf_oh;?1H)R&;N=Uf#T7NIK=-*iyqrj zD_?OZ)JedsY#}8w_bd+`0Tsp{tWyxBK2E=H$S>p{SSZWK0MKh zq{CfAu(}yXD>x3fhEewMQS$NAW7|~%tn)N|xtoN60LPw>YR`<5B)_aGS=8;8Sps`g z=2-$)MFgzMm-X<`cLzgR0>?hz1NlZl2R&m4(MK!K6bNZkh7tq<_l?1|UfrQWHb4LV zKJ?G;4+jSalQc;RgmL6q)+X$YE@^2o4{KxOeC}Qqo>cnvnby1%vto(QG!PT;#=1_% zyj;jC=HBB*Fxy~h5sb{(HeuA)tJsN$88`8R|CD54`|jYY|M&a9-~avo@ArTI?0^3o P00960v;Lt-0OA4w!osw1 literal 0 HcmV?d00001 diff --git a/charts/longhorn/105.1.0+up1.7.2/.helmignore b/charts/longhorn/105.1.0+up1.7.2/.helmignore new file mode 100644 index 0000000000..f0c1319444 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/.helmignore @@ -0,0 +1,21 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj diff --git a/charts/longhorn/105.1.0+up1.7.2/Chart.yaml b/charts/longhorn/105.1.0+up1.7.2/Chart.yaml new file mode 100644 index 0000000000..355db65fd7 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/Chart.yaml @@ -0,0 +1,39 @@ +annotations: + catalog.cattle.io/auto-install: longhorn-crd=match + catalog.cattle.io/certified: rancher + catalog.cattle.io/display-name: Longhorn + catalog.cattle.io/kube-version: '>= 1.23.0-0' + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/permits-os: linux,windows + catalog.cattle.io/provides-gvr: longhorn.io/v1beta1 + catalog.cattle.io/rancher-version: '>= 2.10.0-0 < 2.11.0-0' + catalog.cattle.io/release-name: longhorn + catalog.cattle.io/type: cluster-tool + catalog.cattle.io/upstream-version: 1.7.2 +apiVersion: v1 +appVersion: v1.7.2 +description: Longhorn is a distributed block storage system for Kubernetes. +home: https://github.com/longhorn/longhorn +icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/longhorn/icon/color/longhorn-icon-color.png +keywords: +- longhorn +- storage +- distributed +- block +- device +- iscsi +- nfs +maintainers: +- email: maintainers@longhorn.io + name: Longhorn maintainers +name: longhorn +sources: +- https://github.com/longhorn/longhorn +- https://github.com/longhorn/longhorn-engine +- https://github.com/longhorn/longhorn-instance-manager +- https://github.com/longhorn/longhorn-share-manager +- https://github.com/longhorn/longhorn-manager +- https://github.com/longhorn/longhorn-ui +- https://github.com/longhorn/longhorn-tests +- https://github.com/longhorn/backing-image-manager +version: 105.1.0+up1.7.2 diff --git a/charts/longhorn/105.1.0+up1.7.2/README.md b/charts/longhorn/105.1.0+up1.7.2/README.md new file mode 100644 index 0000000000..adb190be3b --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/README.md @@ -0,0 +1,50 @@ +# Longhorn Chart + +> **Important**: Please install the Longhorn chart in the `longhorn-system` namespace only. + +> **Warning**: Longhorn doesn't support downgrading from a higher version to a lower version. + +> **Note**: Use Helm 3 when installing and upgrading Longhorn. Helm 2 is [no longer supported](https://helm.sh/blog/helm-2-becomes-unsupported/). + +## Source Code + +Longhorn is 100% open source software. Project source code is spread across a number of repos: + +1. Longhorn Engine -- Core controller/replica logic https://github.com/longhorn/longhorn-engine +2. Longhorn Instance Manager -- Controller/replica instance lifecycle management https://github.com/longhorn/longhorn-instance-manager +3. Longhorn Share Manager -- NFS provisioner that exposes Longhorn volumes as ReadWriteMany volumes. https://github.com/longhorn/longhorn-share-manager +4. Backing Image Manager -- Backing image file lifecycle management. https://github.com/longhorn/backing-image-manager +5. Longhorn Manager -- Longhorn orchestration, includes CSI driver for Kubernetes https://github.com/longhorn/longhorn-manager +6. Longhorn UI -- Dashboard https://github.com/longhorn/longhorn-ui + +## Prerequisites + +1. A container runtime compatible with Kubernetes (Docker v1.13+, containerd v1.3.7+, etc.) +2. Kubernetes >= v1.21 +3. Make sure `bash`, `curl`, `findmnt`, `grep`, `awk` and `blkid` has been installed in all nodes of the Kubernetes cluster. +4. Make sure `open-iscsi` has been installed, and the `iscsid` daemon is running on all nodes of the Kubernetes cluster. For GKE, recommended Ubuntu as guest OS image since it contains `open-iscsi` already. + +## Upgrading to Kubernetes v1.25+ + +Starting in Kubernetes v1.25, [Pod Security Policies](https://kubernetes.io/docs/concepts/security/pod-security-policy/) have been removed from the Kubernetes API. + +As a result, **before upgrading to Kubernetes v1.25** (or on a fresh install in a Kubernetes v1.25+ cluster), users are expected to perform an in-place upgrade of this chart with `enablePSP` set to `false` if it has been previously set to `true`. + +> **Note:** +> If you upgrade your cluster to Kubernetes v1.25+ before removing PSPs via a `helm upgrade` (even if you manually clean up resources), **it will leave the Helm release in a broken state within the cluster such that further Helm operations will not work (`helm uninstall`, `helm upgrade`, etc.).** +> +> If your charts get stuck in this state, you may have to clean up your Helm release secrets. +Upon setting `enablePSP` to false, the chart will remove any PSP resources deployed on its behalf from the cluster. This is the default setting for this chart. + +As a replacement for PSPs, [Pod Security Admission](https://kubernetes.io/docs/concepts/security/pod-security-admission/) should be used. Please consult the Longhorn docs for more details on how to configure your chart release namespaces to work with the new Pod Security Admission and apply Pod Security Standards. + +## Uninstallation + +To prevent Longhorn from being accidentally uninstalled (which leads to data lost), we introduce a new setting, deleting-confirmation-flag. If this flag is **false**, the Longhorn uninstallation job will fail. Set this flag to **true** to allow Longhorn uninstallation. You can set this flag using setting page in Longhorn UI or `kubectl -n longhorn-system patch -p '{"value": "true"}' --type=merge lhs deleting-confirmation-flag` + +To prevent damage to the Kubernetes cluster, we recommend deleting all Kubernetes workloads using Longhorn volumes (PersistentVolume, PersistentVolumeClaim, StorageClass, Deployment, StatefulSet, DaemonSet, etc). + +From Rancher Cluster Explorer UI, navigate to Apps page, delete app `longhorn` then app `longhorn-crd` in Installed Apps tab. + +--- +Please see [link](https://github.com/longhorn/longhorn) for more information. diff --git a/charts/longhorn/105.1.0+up1.7.2/app-readme.md b/charts/longhorn/105.1.0+up1.7.2/app-readme.md new file mode 100644 index 0000000000..321e5193c4 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/app-readme.md @@ -0,0 +1,27 @@ +# Longhorn + +Longhorn is a lightweight, reliable and easy to use distributed block storage system for Kubernetes. Once deployed, users can leverage persistent volumes provided by Longhorn. + +Longhorn creates a dedicated storage controller for each volume and synchronously replicates the volume across multiple replicas stored on multiple nodes. The storage controller and replicas are themselves orchestrated using Kubernetes. Longhorn supports snapshots, backups and even allows you to schedule recurring snapshots and backups! + +**Important**: Please install Longhorn chart in `longhorn-system` namespace only. + +**Warning**: Longhorn doesn't support downgrading from a higher version to a lower version. + +[Chart Documentation](https://github.com/longhorn/longhorn/blob/master/chart/README.md) + + +## Upgrading to Kubernetes v1.25+ + +Starting in Kubernetes v1.25, [Pod Security Policies](https://kubernetes.io/docs/concepts/security/pod-security-policy/) have been removed from the Kubernetes API. + +As a result, **before upgrading to Kubernetes v1.25** (or on a fresh install in a Kubernetes v1.25+ cluster), users are expected to perform an in-place upgrade of this chart with `enablePSP` set to `false` if it has been previously set to `true`. + +> **Note:** +> If you upgrade your cluster to Kubernetes v1.25+ before removing PSPs via a `helm upgrade` (even if you manually clean up resources), **it will leave the Helm release in a broken state within the cluster such that further Helm operations will not work (`helm uninstall`, `helm upgrade`, etc.).** +> +> If your charts get stuck in this state, please consult the Rancher docs on how to clean up your Helm release secrets. + +Upon setting `enablePSP` to false, the chart will remove any PSP resources deployed on its behalf from the cluster. This is the default setting for this chart. + +As a replacement for PSPs, [Pod Security Admission](https://kubernetes.io/docs/concepts/security/pod-security-admission/) should be used. Please consult the Rancher docs for more details on how to configure your chart release namespaces to work with the new Pod Security Admission and apply Pod Security Standards. \ No newline at end of file diff --git a/charts/longhorn/105.1.0+up1.7.2/questions.yaml b/charts/longhorn/105.1.0+up1.7.2/questions.yaml new file mode 100644 index 0000000000..89c8dbe105 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/questions.yaml @@ -0,0 +1,974 @@ +categories: +- storage +namespace: longhorn-system +questions: +- variable: image.defaultImage + default: "true" + description: "Use default Longhorn images" + label: Use Default Images + type: boolean + show_subquestion_if: false + group: "Longhorn Images" + subquestions: + - variable: image.longhorn.manager.repository + default: rancher/mirrored-longhornio-longhorn-manager + description: "Repository for the Longhorn Manager image." + type: string + label: Longhorn Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.manager.tag + default: v1.7.2 + description: "Tag for the Longhorn Manager image." + type: string + label: Longhorn Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.engine.repository + default: rancher/mirrored-longhornio-longhorn-engine + description: "Repository for the Longhorn Engine image." + type: string + label: Longhorn Engine Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.engine.tag + default: v1.7.2 + description: "Tag for the Longhorn Engine image." + type: string + label: Longhorn Engine Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.ui.repository + default: rancher/mirrored-longhornio-longhorn-ui + description: "Repository for the Longhorn UI image." + type: string + label: Longhorn UI Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.ui.tag + default: v1.7.2 + description: "Tag for the Longhorn UI image." + type: string + label: Longhorn UI Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.instanceManager.repository + default: rancher/mirrored-longhornio-longhorn-instance-manager + description: "Repository for the Longhorn Instance Manager image." + type: string + label: Longhorn Instance Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.instanceManager.tag + default: v1.7.2 + description: "Tag for the Longhorn Instance Manager image." + type: string + label: Longhorn Instance Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.shareManager.repository + default: rancher/mirrored-longhornio-longhorn-share-manager + description: "Repository for the Longhorn Share Manager image." + type: string + label: Longhorn Share Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.shareManager.tag + default: v1.7.2 + description: "Tag for the Longhorn Share Manager image." + type: string + label: Longhorn Share Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.backingImageManager.repository + default: rancher/mirrored-longhornio-backing-image-manager + description: "Repository for the Backing Image Manager image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn Backing Image Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.backingImageManager.tag + default: v1.7.2 + description: "Tag for the Backing Image Manager image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn Backing Image Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.supportBundleKit.repository + default: rancher/mirrored-longhornio-support-bundle-kit + description: "Repository for the Longhorn Support Bundle Manager image." + type: string + label: Longhorn Support Bundle Kit Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.supportBundleKit.tag + default: v0.0.45 + description: "Tag for the Longhorn Support Bundle Manager image." + type: string + label: Longhorn Support Bundle Kit Image Tag + group: "Longhorn Images Settings" + - variable: image.csi.attacher.repository + default: rancher/mirrored-longhornio-csi-attacher + description: "Repository for the CSI attacher image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Attacher Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.attacher.tag + default: v4.7.0 + description: "Tag for the CSI attacher image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Attacher Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.provisioner.repository + default: rancher/mirrored-longhornio-csi-provisioner + description: "Repository for the CSI Provisioner image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Provisioner Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.provisioner.tag + default: v4.0.1-20241007 + description: "Tag for the CSI Provisioner image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Provisioner Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.nodeDriverRegistrar.repository + default: rancher/mirrored-longhornio-csi-node-driver-registrar + description: "Repository for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Node Driver Registrar Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.nodeDriverRegistrar.tag + default: v2.12.0 + description: "Tag for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Node Driver Registrar Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.resizer.repository + default: rancher/mirrored-longhornio-csi-resizer + description: "Repository for the CSI Resizer image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Resizer Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.resizer.tag + default: v1.12.0 + description: "Tag for the CSI Resizer image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Resizer Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.snapshotter.repository + default: rancher/mirrored-longhornio-csi-snapshotter + description: "Repository for the CSI Snapshotter image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Snapshotter Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.snapshotter.tag + default: v7.0.2-20241007 + description: "Tag for the CSI Snapshotter image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Snapshotter Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.livenessProbe.repository + default: rancher/mirrored-longhornio-livenessprobe + description: "Repository for the CSI liveness probe image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Liveness Probe Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.livenessProbe.tag + default: v2.14.0 + description: "Tag for the CSI liveness probe image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Liveness Probe Image Tag + group: "Longhorn CSI Driver Images" +- variable: privateRegistry.registryUrl + label: Private registry URL + description: "URL of a private registry. When unspecified, Longhorn uses the default system registry." + group: "Private Registry Settings" + type: string + default: "" +- variable: privateRegistry.registrySecret + label: Private registry secret name + description: "Kubernetes secret that allows you to pull images from a private registry. This setting applies only when creation of private registry secrets is enabled. You must include the private registry name in the secret name." + group: "Private Registry Settings" + type: string + default: "" +- variable: privateRegistry.createSecret + default: "true" + description: "Setting that allows you to create a private registry secret." + type: boolean + group: "Private Registry Settings" + label: Create Secret for Private Registry Settings + show_subquestion_if: true + subquestions: + - variable: privateRegistry.registryUser + label: Private registry user + description: "User account used for authenticating with a private registry." + type: string + default: "" + - variable: privateRegistry.registryPasswd + label: Private registry password + description: "Password for authenticating with a private registry." + type: password + default: "" +- variable: longhorn.default_setting + default: "false" + description: "Customize the default settings before installing Longhorn for the first time. This option will only work if the cluster hasn't installed Longhorn." + label: "Customize Default Settings" + type: boolean + show_subquestion_if: true + group: "Longhorn Default Settings" + subquestions: + - variable: csi.kubeletRootDir + default: + description: "kubelet root directory. When unspecified, Longhorn uses the default value." + type: string + label: Kubelet Root Directory + group: "Longhorn CSI Driver Settings" + - variable: csi.attacherReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Attacher. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Attacher replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.provisionerReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Provisioner. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Provisioner replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.resizerReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Resizer. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Resizer replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.snapshotterReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Snapshotter. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Snapshotter replica count + group: "Longhorn CSI Driver Settings" + - variable: defaultSettings.backupTarget + label: Backup Target + description: "Endpoint used to access the backupstore. (Options: \"NFS\", \"CIFS\", \"AWS\", \"GCP\", \"AZURE\")" + group: "Longhorn Default Settings" + type: string + default: + - variable: defaultSettings.backupTargetCredentialSecret + label: Backup Target Credential Secret + description: "Name of the Kubernetes secret associated with the backup target." + group: "Longhorn Default Settings" + type: string + default: + - variable: defaultSettings.allowRecurringJobWhileVolumeDetached + label: Allow Recurring Job While Volume Is Detached + description: 'Setting that allows Longhorn to automatically attach a volume and create snapshots or backups when recurring jobs are run.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.snapshotMaxCount + label: Snapshot Maximum Count + description: 'Maximum snapshot count for a volume. The value should be between 2 to 250.' + group: "Longhorn Default Settings" + type: int + min: 2 + max: 250 + default: 250 + - variable: defaultSettings.createDefaultDiskLabeledNodes + label: Create Default Disk on Labeled Nodes + description: 'Setting that allows Longhorn to automatically create a default disk only on nodes with the label "node.longhorn.io/create-default-disk=true" (if no other disks exist). When this setting is disabled, Longhorn creates a default disk on each node that is added to the cluster.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.defaultDataPath + label: Default Data Path + description: 'Default path for storing data on a host. The default value is "/var/lib/longhorn/".' + group: "Longhorn Default Settings" + type: string + default: "/var/lib/longhorn/" + - variable: defaultSettings.defaultDataLocality + label: Default Data Locality + description: 'Default data locality. A Longhorn volume has data locality if a local replica of the volume exists on the same node as the pod that is using the volume.' + group: "Longhorn Default Settings" + type: enum + options: + - "disabled" + - "best-effort" + default: "disabled" + - variable: defaultSettings.replicaSoftAntiAffinity + label: Replica Node Level Soft Anti-Affinity + description: 'Allow scheduling on nodes with existing healthy replicas of the same volume. By default, false.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.replicaAutoBalance + label: Replica Auto Balance + description: 'Enable this setting automatically re-balances replicas when discovered an available node.' + group: "Longhorn Default Settings" + type: enum + options: + - "disabled" + - "least-effort" + - "best-effort" + default: "disabled" + - variable: defaultSettings.storageOverProvisioningPercentage + label: Storage Over Provisioning Percentage + description: "Percentage of storage that can be allocated relative to hard drive capacity. The default value is 100." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 100 + - variable: defaultSettings.storageMinimalAvailablePercentage + label: Storage Minimal Available Percentage + description: "If the minimum available disk capacity exceeds the actual percentage of available disk capacity, the disk becomes unschedulable until more space is freed up. By default, 25." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 100 + default: 25 + - variable: defaultSettings.storageReservedPercentageForDefaultDisk + label: Storage Reserved Percentage For Default Disk + description: "The reserved percentage specifies the percentage of disk space that will not be allocated to the default disk on each new Longhorn node." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 100 + default: 30 + - variable: defaultSettings.upgradeChecker + label: Enable Upgrade Checker + description: 'Upgrade Checker that periodically checks for new Longhorn versions. When a new version is available, a notification appears on the Longhorn UI. This setting is enabled by default.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.defaultReplicaCount + label: Default Replica Count + description: "Default number of replicas for volumes created using the Longhorn UI. For Kubernetes configuration, modify the `numberOfReplicas` field in the StorageClass. The default value is \"3\"." + group: "Longhorn Default Settings" + type: int + min: 1 + max: 20 + default: 3 + - variable: defaultSettings.defaultLonghornStaticStorageClass + label: Default Longhorn Static StorageClass Name + description: "Default Longhorn StorageClass. \"storageClassName\" is assigned to PVs and PVCs that are created for an existing Longhorn volume. \"storageClassName\" can also be used as a label, so it is possible to use a Longhorn StorageClass to bind a workload to an existing PV without creating a Kubernetes StorageClass object. The default value is \"longhorn-static\"." + group: "Longhorn Default Settings" + type: string + default: "longhorn-static" + - variable: defaultSettings.backupstorePollInterval + label: Backupstore Poll Interval + description: "Number of seconds that Longhorn waits before checking the backupstore for new backups. The default value is \"300\". When the value is \"0\", polling is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 300 + - variable: defaultSettings.failedBackupTTL + label: Failed Backup Time to Live + description: "Number of minutes that Longhorn keeps a failed backup resource. When the value is \"0\", automatic deletion is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1440 + - variable: defaultSettings.restoreVolumeRecurringJobs + label: Restore Volume Recurring Jobs + description: "Restore recurring jobs from the backup volume on the backup target and create recurring jobs if not exist during a backup restoration." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.recurringSuccessfulJobsHistoryLimit + label: Cronjob Successful Jobs History Limit + description: "This setting specifies how many successful backup or snapshot job histories should be retained. History will not be retained if the value is 0." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.recurringFailedJobsHistoryLimit + label: Cronjob Failed Jobs History Limit + description: 'Maximum number of failed recurring backup and snapshot jobs to be retained. When the value is "0", a history of failed recurring jobs is not retained.' + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.recurringJobMaxRetention + label: Maximum Retention Number for Recurring Job + description: "Maximum number of snapshots or backups to be retained." + group: "Longhorn Default Settings" + type: int + default: 100 + - variable: defaultSettings.supportBundleFailedHistoryLimit + label: SupportBundle Failed History Limit + description: "This setting specifies how many failed support bundles can exist in the cluster. Set this value to **0** to have Longhorn automatically purge all failed support bundles." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.autoSalvage + label: Automatic salvage + description: "Setting that allows Longhorn to automatically salvage volumes when all replicas become faulty (for example, when the network connection is interrupted). Longhorn determines which replicas are usable and then uses these replicas for the volume. This setting is enabled by default." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly + label: Automatically Delete Workload Pod when The Volume Is Detached Unexpectedly + description: 'Setting that allows Longhorn to automatically delete a workload pod that is managed by a controller (for example, daemonset) whenever a Longhorn volume is detached unexpectedly (for example, during Kubernetes upgrades). After deletion, the controller restarts the pod and then Kubernetes handles volume reattachment and remounting.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.disableSchedulingOnCordonedNode + label: Disable Scheduling On Cordoned Node + description: "Setting that prevents Longhorn Manager from scheduling replicas on a cordoned Kubernetes node. This setting is enabled by default." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.replicaZoneSoftAntiAffinity + label: Replica Zone Level Soft Anti-Affinity + description: "Allow scheduling new Replicas of Volume to the Nodes in the same Zone as existing healthy Replicas. Nodes don't belong to any Zone will be treated as in the same Zone. Notice that Longhorn relies on label `topology.kubernetes.io/zone=` in the Kubernetes node object to identify the zone. By, default true." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.replicaDiskSoftAntiAffinity + label: Replica Disk Level Soft Anti-Affinity + description: 'Allow scheduling on disks with existing healthy replicas of the same volume. By default, true.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.allowEmptyNodeSelectorVolume + label: Allow Empty Node Selector Volume + description: "Setting that allows scheduling of empty node selector volumes to any node." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.allowEmptyDiskSelectorVolume + label: Allow Empty Disk Selector Volume + description: "Setting that allows scheduling of empty disk selector volumes to any disk." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.nodeDownPodDeletionPolicy + label: Pod Deletion Policy When Node is Down + description: "Policy that defines the action Longhorn takes when a volume is stuck with a StatefulSet or Deployment pod on a node that failed." + group: "Longhorn Default Settings" + type: enum + options: + - "do-nothing" + - "delete-statefulset-pod" + - "delete-deployment-pod" + - "delete-both-statefulset-and-deployment-pod" + default: "do-nothing" + - variable: defaultSettings.nodeDrainPolicy + label: Node Drain Policy + description: "Policy that defines the action Longhorn takes when a node with the last healthy replica of a volume is drained." + group: "Longhorn Default Settings" + type: enum + options: + - "block-for-eviction" + - "block-for-eviction-if-contains-last-replica" + - "block-if-contains-last-replica" + - "allow-if-replica-is-stopped" + - "always-allow" + default: "block-if-contains-last-replica" + - variable: defaultSettings.detachManuallyAttachedVolumesWhenCordoned + label: Detach Manually Attached Volumes When Cordoned + description: "Setting that allows automatic detaching of manually-attached volumes when a node is cordoned." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.priorityClass + label: Priority Class + description: "PriorityClass for system-managed Longhorn components. This setting can help prevent Longhorn components from being evicted under Node Pressure. Longhorn system contains user deployed components (E.g, Longhorn manager, Longhorn driver, Longhorn UI) and system managed components (E.g, instance manager, engine image, CSI driver, etc.) Note that this will be applied to Longhorn user-deployed components by default if there are no priority class values set yet, such as `longhornManager.priorityClass`. WARNING: DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES." + group: "Longhorn Default Settings" + type: string + default: "longhorn-critical" + - variable: defaultSettings.replicaReplenishmentWaitInterval + label: Replica Replenishment Wait Interval + description: "The interval in seconds determines how long Longhorn will at least wait to reuse the existing data on a failed replica rather than directly creating a new replica for a degraded volume." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 600 + - variable: defaultSettings.concurrentReplicaRebuildPerNodeLimit + label: Concurrent Replica Rebuild Per Node Limit + description: "Maximum number of replicas that can be concurrently rebuilt on each node. + WARNING: + - The old setting \"Disable Replica Rebuild\" is replaced by this setting. + - Different from relying on replica starting delay to limit the concurrent rebuilding, if the rebuilding is disabled, replica object replenishment will be directly skipped. + - When the value is 0, the eviction and data locality feature won't work. But this shouldn't have any impact to any current replica rebuild and backup restore." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 5 + - variable: defaultSettings.concurrentVolumeBackupRestorePerNodeLimit + label: Concurrent Volume Backup Restore Per Node Limit + description: "Maximum number of volumes that can be concurrently restored on each node using a backup. When the value is \"0\", restoration of volumes using a backup is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 5 + - variable: defaultSettings.disableRevisionCounter + label: Disable Revision Counter + description: "Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the \"volume-head-xxx.img\" file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. This setting applies only to volumes created using the Longhorn UI." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.systemManagedPodsImagePullPolicy + label: System Managed Pod Image Pull Policy + description: "Image pull policy for system-managed pods, such as Instance Manager, engine images, and CSI Driver. Changes to the image pull policy are applied only after the system-managed pods restart." + group: "Longhorn Default Settings" + type: enum + options: + - "if-not-present" + - "always" + - "never" + default: "if-not-present" + - variable: defaultSettings.allowVolumeCreationWithDegradedAvailability + label: Allow Volume Creation with Degraded Availability + description: "Setting that allows you to create and attach a volume without having all replicas scheduled at the time of creation." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoCleanupSystemGeneratedSnapshot + label: Automatically Cleanup System Generated Snapshot + description: "Setting that allows Longhorn to automatically clean up the system-generated snapshot after replica rebuilding is completed." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoCleanupRecurringJobBackupSnapshot + label: Automatically Cleanup Recurring Job Backup Snapshot + description: "Setting that allows Longhorn to automatically clean up the snapshot generated by a recurring backup job." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit + label: Concurrent Automatic Engine Upgrade Per Node Limit + description: "Maximum number of engines that are allowed to concurrently upgrade on each node after Longhorn Manager is upgraded. When the value is \"0\", Longhorn does not automatically upgrade volume engines to the new default engine image version." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 0 + - variable: defaultSettings.backingImageCleanupWaitInterval + label: Backing Image Cleanup Wait Interval + description: "Number of minutes that Longhorn waits before cleaning up the backing image file when no replicas in the disk are using it." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 60 + - variable: defaultSettings.backingImageRecoveryWaitInterval + label: Backing Image Recovery Wait Interval + description: "Number of seconds that Longhorn waits before downloading a backing image file again when the status of all image disk files changes to \"failed\" or \"unknown\"." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 300 + - variable: defaultSettings.guaranteedInstanceManagerCPU + label: Guaranteed Instance Manager CPU + description: "Percentage of the total allocatable CPU resources on each node to be reserved for each instance manager pod when the V1 Data Engine is enabled. The default value is \"12\". + WARNING: + - Value 0 means removing the CPU requests from spec of instance manager pods. + - Considering the possible number of new instance manager pods in a further system upgrade, this integer value ranges from 0 to 40. + - One more set of instance manager pods may need to be deployed when the Longhorn system is upgraded. If current available CPUs of the nodes are not enough for the new instance manager pods, you need to detach the volumes using the oldest instance manager pods so that Longhorn can clean up the old pods automatically and release the CPU resources. And the new pods with the latest instance manager image will be launched then. + - This global setting will be ignored for a node if the field \"InstanceManagerCPURequest\" on the node is set. + - After this setting is changed, all instance manager pods using this global setting on all the nodes will be automatically restarted. In other words, DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 40 + default: 12 + - variable: defaultSettings.logLevel + label: Log Level + description: 'Log levels that indicate the type and severity of logs in Longhorn Manager. The default value is "Info". (Options: "Panic", "Fatal", "Error", "Warn", "Info", "Debug", "Trace")' + group: "Longhorn Default Settings" + type: string + default: "Info" + - variable: defaultSettings.disableSnapshotPurge + label: Disable Snapshot Purge + description: "Setting that temporarily prevents all attempts to purge volume snapshots." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.freezeFilesystemForSnapshot + description: "Setting that freezes the filesystem on the root partition before a snapshot is created." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.kubernetesClusterAutoscalerEnabled + label: Kubernetes Cluster Autoscaler Enabled (Experimental) + description: "Setting that notifies Longhorn that the cluster is using the Kubernetes Cluster Autoscaler. + WARNING: + - Replica rebuilding could be expensive because nodes with reusable replicas could get removed by the Kubernetes Cluster Autoscaler." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.orphanAutoDeletion + label: Orphaned Data Cleanup + description: "Setting that allows Longhorn to automatically delete an orphaned resource and the corresponding data (for example, stale replicas). Orphaned resources on failed or unknown nodes are not automatically cleaned up." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.storageNetwork + label: Storage Network + description: "Longhorn uses the storage network for in-cluster data traffic. Leave this blank to use the Kubernetes cluster network. + WARNING: + - This setting should change after detaching all Longhorn volumes, as some of the Longhorn system component pods will get recreated to apply the setting. Longhorn will try to block this setting update when there are attached volumes." + group: "Longhorn Default Settings" + type: string + default: +- variable: defaultSettings.deletingConfirmationFlag + label: Deleting Confirmation Flag + description: "Flag that prevents accidental uninstallation of Longhorn." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.engineReplicaTimeout + label: Timeout between Engine and Replica + description: "Timeout between the Longhorn Engine and replicas. Specify a value between \"8\" and \"30\" seconds. The default value is \"8\"." + group: "Longhorn Default Settings" + type: int + default: "8" +- variable: defaultSettings.snapshotDataIntegrity + label: Snapshot Data Integrity + description: "This setting allows users to enable or disable snapshot hashing and data integrity checking." + group: "Longhorn Default Settings" + type: string + default: "disabled" +- variable: defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation + label: Immediate Snapshot Data Integrity Check After Creating a Snapshot + description: "Hashing snapshot disk files impacts the performance of the system. The immediate snapshot hashing and checking can be disabled to minimize the impact after creating a snapshot." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.snapshotDataIntegrityCronjob + label: Snapshot Data Integrity Check CronJob + description: "Unix-cron string format. The setting specifies when Longhorn checks the data integrity of snapshot disk files." + group: "Longhorn Default Settings" + type: string + default: "0 0 */7 * *" +- variable: defaultSettings.removeSnapshotsDuringFilesystemTrim + label: Remove Snapshots During Filesystem Trim + description: "This setting allows Longhorn filesystem trim feature to automatically mark the latest snapshot and its ancestors as removed and stops at the snapshot containing multiple children." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.fastReplicaRebuildEnabled + label: Fast Replica Rebuild Enabled + description: "Setting that allows fast rebuilding of replicas using the checksum of snapshot disk files. Before enabling this setting, you must set the snapshot-data-integrity value to \"enable\" or \"fast-check\"." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.replicaFileSyncHttpClientTimeout + label: Timeout of HTTP Client to Replica File Sync Server + description: "In seconds. The setting specifies the HTTP client timeout to the file sync server." + group: "Longhorn Default Settings" + type: int + default: "30" +- variable: defaultSettings.longGRPCTimeOut + label: Long gRPC Timeout + description: "Number of seconds that Longhorn allows for the completion of replica rebuilding and snapshot cloning operations." + group: "Longhorn Default Settings" + type: int + default: "86400" +- variable: defaultSettings.backupCompressionMethod + label: Backup Compression Method + description: "Setting that allows you to specify a backup compression method." + group: "Longhorn Default Settings" + type: string + default: "lz4" +- variable: defaultSettings.backupConcurrentLimit + label: Backup Concurrent Limit Per Backup + description: "Maximum number of worker threads that can concurrently run for each backup." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 2 +- variable: defaultSettings.restoreConcurrentLimit + label: Restore Concurrent Limit Per Backup + description: "This setting controls how many worker threads per restore concurrently." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 2 +- variable: defaultSettings.allowCollectingLonghornUsageMetrics + label: Allow Collecting Longhorn Usage Metrics + description: "Setting that allows Longhorn to periodically collect anonymous usage data for product improvement purposes. Longhorn sends collected data to the [Upgrade Responder](https://github.com/longhorn/upgrade-responder) server, which is the data source of the Longhorn Public Metrics Dashboard (https://metrics.longhorn.io). The Upgrade Responder server does not store data that can be used to identify clients, including IP addresses." + group: "Longhorn Default Settings" + type: boolean + default: true +- variable: defaultSettings.v1DataEngine + label: V1 Data Engine + description: "Setting that allows you to enable the V1 Data Engine." + group: "Longhorn V1 Data Engine Settings" + type: boolean + default: true +- variable: defaultSettings.v2DataEngine + label: V2 Data Engine + description: "Setting that allows you to enable the V2 Data Engine, which is based on the Storage Performance Development Kit (SPDK). The V2 Data Engine is a preview feature and should not be used in production environments. + WARNING: + - DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES. Longhorn will block this setting update when there are attached volumes. + - When the V2 Data Engine is enabled, each instance-manager pod utilizes 1 CPU core. This high CPU usage is attributed to the spdk_tgt process running within each instance-manager pod. The spdk_tgt process is responsible for handling input/output (IO) operations and requires intensive polling. As a result, it consumes 100% of a dedicated CPU core to efficiently manage and process the IO requests, ensuring optimal performance and responsiveness for storage operations." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: boolean + default: false +- variable: defaultSettings.v2DataEngineHugepageLimit + label: V2 Data Engine + description: "This allows users to configure maximum huge page size (in MiB) for the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: int + default: "2048" +- variable: defaultSettings.v2DataEngineLogLevel + label: V2 Data Engine + description: "Setting that allows you to configure the log level of the SPDK target daemon (spdk_tgt) of the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: enum + options: + - "Disabled" + - "Error" + - "Warn" + - "Notice" + - "Info" + - "Debug" + default: "Notice" +- variable: defaultSettings.v2DataEngineLogFlags + label: V2 Data Engine + description: "Setting that allows you to configure the log flags of the SPDK target daemon (spdk_tgt) of the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: string + default: +- variable: defaultSettings.autoCleanupSnapshotWhenDeleteBackup + label: Auto Cleanup Snapshot When Delete Backup + description: "Setting that automatically cleans up the snapshot when the backup is deleted." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.rwxVolumeFastFailover + label: RWX Volume Fast Failover (Experimental) + description: "Turn on logic to detect and move RWX volumes quickly on node failure." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: persistence.defaultClass + default: "true" + description: "Setting that allows you to specify the default Longhorn StorageClass." + label: Default Storage Class + group: "Longhorn Storage Class Settings" + required: true + type: boolean +- variable: persistence.reclaimPolicy + label: Storage Class Retain Policy + description: "Reclaim policy that provides instructions for handling of a volume after its claim is released. (Options: \"Retain\", \"Delete\")" + group: "Longhorn Storage Class Settings" + required: true + type: enum + options: + - "Delete" + - "Retain" + default: "Delete" +- variable: persistence.disableRevisionCounter + label: Default Storage Class Disable Revision Counter + description: "Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the volume-head-xxx.img file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. (Options: \"true\", \"false\")" + group: "Longhorn Storage Class Settings" + required: true + type: enum + options: + - "true" + - "false" + default: "true" +- variable: persistence.defaultClassReplicaCount + description: "Replica count of the default Longhorn StorageClass." + label: Default Storage Class Replica Count + group: "Longhorn Storage Class Settings" + type: int + min: 1 + max: 10 + default: 3 +- variable: persistence.defaultDataLocality + description: "Data locality of the default Longhorn StorageClass. (Options: \"disabled\", \"best-effort\")" + label: Default Storage Class Data Locality + group: "Longhorn Storage Class Settings" + type: enum + options: + - "disabled" + - "best-effort" + default: "disabled" +- variable: persistence.recurringJobSelector.enable + description: "Setting that allows you to enable the recurring job selector for a Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Recurring Job Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.recurringJobSelector.jobList + description: 'Recurring job selector for a Longhorn StorageClass. Ensure that quotes are used correctly when specifying job parameters. (Example: `[{"name":"backup", "isGroup":true}]`)' + label: Storage Class Recurring Job Selector List + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.defaultDiskSelector.enable + description: "Setting that allows you to enable the disk selector for the default Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Disk Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.defaultDiskSelector.selector + label: Storage Class Disk Selector + description: 'Disk selector for the default Longhorn StorageClass. Longhorn uses only disks with the specified tags for storing volume data. (Examples: "nvme,sata")' + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.defaultNodeSelector.enable + description: "Setting that allows you to enable the node selector for the default Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Node Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.defaultNodeSelector.selector + label: Storage Class Node Selector + description: 'Node selector for the default Longhorn StorageClass. Longhorn uses only nodes with the specified tags for storing volume data. (Examples: "storage,fast")' + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.backingImage.enable + description: "Setting that allows you to use a backing image in a Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Default Storage Class Backing Image + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.backingImage.name + description: 'Backing image to be used for creating and restoring volumes in a Longhorn StorageClass. When no backing images are available, specify the data source type and parameters that Longhorn can use to create a backing image.' + label: Storage Class Backing Image Name + group: "Longhorn Storage Class Settings" + type: string + default: + - variable: persistence.backingImage.expectedChecksum + description: 'Expected SHA-512 checksum of a backing image used in a Longhorn StorageClass. + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - It is not recommended to set this field if the data source type is \"export-from-volume\".' + label: Storage Class Backing Image Expected SHA512 Checksum + group: "Longhorn Storage Class Settings" + type: string + default: + - variable: persistence.backingImage.dataSourceType + description: 'Data source type of a backing image used in a Longhorn StorageClass. If the backing image exists in the cluster, Longhorn uses this setting to verify the image. If the backing image does not exist, Longhorn creates one using the specified data source type. + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - As for backing image creation with data source type \"upload\", it is recommended to do it via UI rather than StorageClass here. Uploading requires file data sending to the Longhorn backend after the object creation, which is complicated if you want to handle it manually.' + label: Storage Class Backing Image Data Source Type + group: "Longhorn Storage Class Settings" + type: enum + options: + - "" + - "download" + - "upload" + - "export-from-volume" + default: "" + - variable: persistence.backingImage.dataSourceParameters + description: "Data source parameters of a backing image used in a Longhorn StorageClass. You can specify a JSON string of a map. (Example: `'{\"url\":\"https://backing-image-example.s3-region.amazonaws.com/test-backing-image\"}'`) + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - Be careful of the quotes here." + label: Storage Class Backing Image Data Source Parameters + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.removeSnapshotsDuringFilesystemTrim + description: "Setting that allows you to enable automatic snapshot removal during filesystem trim for a Longhorn StorageClass. (Options: \"ignored\", \"enabled\", \"disabled\")" + label: Default Storage Class Remove Snapshots During Filesystem Trim + group: "Longhorn Storage Class Settings" + type: enum + options: + - "ignored" + - "enabled" + - "disabled" + default: "ignored" +- variable: ingress.enabled + default: "false" + description: "Expose app using Layer 7 Load Balancer - ingress" + type: boolean + group: "Services and Load Balancing" + label: Expose app using Layer 7 Load Balancer + show_subquestion_if: true + subquestions: + - variable: ingress.host + default: "xip.io" + description: "Hostname of the Layer 7 load balancer." + type: hostname + required: true + label: Layer 7 Load Balancer Hostname + - variable: ingress.path + default: "/" + description: "Default ingress path. You can access the Longhorn UI by following the full ingress path {{host}}+{{path}}." + type: string + required: true + label: Ingress Path + - variable: ingress.pathType + default: "ImplementationSpecific" + description: "Path type for the ingress. (Options: \"ImplementationSpecific\", \"Exact\", \"Prefix\")" + type: enum + options: + - "ImplementationSpecific" + - "Exact" + - "Prefix" + required: true + label: Ingress Path Type +- variable: service.ui.type + default: "Rancher-Proxy" + description: "Service type for Longhorn UI. (Options: \"ClusterIP\", \"NodePort\", \"LoadBalancer\", \"Rancher-Proxy\")" + type: enum + options: + - "ClusterIP" + - "NodePort" + - "LoadBalancer" + - "Rancher-Proxy" + label: Longhorn UI Service + show_if: "ingress.enabled=false" + group: "Services and Load Balancing" + show_subquestion_if: "NodePort" + subquestions: + - variable: service.ui.nodePort + default: "" + description: "NodePort port number for Longhorn UI. When unspecified, Longhorn selects a free port between 30000 and 32767." + type: int + min: 30000 + max: 32767 + show_if: "service.ui.type=NodePort||service.ui.type=LoadBalancer" + label: UI Service NodePort number +- variable: enablePSP + default: "false" + description: "Setting that allows you to enable pod security policies (PSPs) that allow privileged Longhorn pods to start. This setting applies only to clusters running Kubernetes 1.25 and earlier, and with the built-in Pod Security admission controller enabled." + label: Pod Security Policy + type: boolean + group: "Other Settings" +- variable: global.cattle.windowsCluster.enabled + default: "false" + description: "Setting that allows Longhorn to run on a Rancher Windows cluster." + label: Rancher Windows Cluster + type: boolean + group: "Other Settings" +- variable: networkPolicies.enabled + description: "Setting that allows you to enable network policies that control access to Longhorn pods. + Warning: The Rancher Proxy will not work if this feature is enabled and a custom NetworkPolicy must be added." + group: "Other Settings" + label: Network Policies + default: "false" + type: boolean + subquestions: + - variable: networkPolicies.type + label: Network Policies for Ingress + description: "Distribution that determines the policy for allowing access for an ingress. (Options: \"k3s\", \"rke2\", \"rke1\")" + show_if: "networkPolicies.enabled=true&&ingress.enabled=true" + type: enum + default: "rke2" + options: + - "rke1" + - "rke2" + - "k3s" + - variable: defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU + label: Guaranteed Instance Manager CPU for V2 Data Engine + description: 'Number of millicpus on each node to be reserved for each Instance Manager pod when the V2 Data Engine is enabled. The default value is "1250". + WARNING: + - Specifying a value of 0 disables CPU requests for instance manager pods. You must specify an integer between 1000 and 8000. + - This is a global setting. Modifying the value triggers an automatic restart of the instance manager pods. Do not modify the value while volumes are still attached." + group: "Longhorn Default Settings' + type: int + min: 1000 + max: 8000 + default: 1250 diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/NOTES.txt b/charts/longhorn/105.1.0+up1.7.2/templates/NOTES.txt new file mode 100644 index 0000000000..cca7cd77b9 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/NOTES.txt @@ -0,0 +1,5 @@ +Longhorn is now installed on the cluster! + +Please wait a few minutes for other Longhorn components such as CSI deployments, Engine Images, and Instance Managers to be initialized. + +Visit our documentation at https://longhorn.io/docs/ diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/_helpers.tpl b/charts/longhorn/105.1.0+up1.7.2/templates/_helpers.tpl new file mode 100644 index 0000000000..3fbc2ac02f --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/_helpers.tpl @@ -0,0 +1,66 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "longhorn.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +*/}} +{{- define "longhorn.fullname" -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "longhorn.managerIP" -}} +{{- $fullname := (include "longhorn.fullname" .) -}} +{{- printf "http://%s-backend:9500" $fullname | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "secret" }} +{{- printf "{\"auths\": {\"%s\": {\"auth\": \"%s\"}}}" .Values.privateRegistry.registryUrl (printf "%s:%s" .Values.privateRegistry.registryUser .Values.privateRegistry.registryPasswd | b64enc) | b64enc }} +{{- end }} + +{{- /* +longhorn.labels generates the standard Helm labels. +*/ -}} +{{- define "longhorn.labels" -}} +app.kubernetes.io/name: {{ template "longhorn.name" . }} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +app.kubernetes.io/instance: {{ .Release.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +{{- end -}} + + +{{- define "system_default_registry" -}} +{{- if .Values.global.cattle.systemDefaultRegistry -}} +{{- printf "%s/" .Values.global.cattle.systemDefaultRegistry -}} +{{- else -}} +{{- "" -}} +{{- end -}} +{{- end -}} + +{{- define "registry_url" -}} +{{- if .Values.privateRegistry.registryUrl -}} +{{- printf "%s/" .Values.privateRegistry.registryUrl -}} +{{- else -}} +{{ include "system_default_registry" . }} +{{- end -}} +{{- end -}} + +{{- /* + define the longhorn release namespace +*/ -}} +{{- define "release_namespace" -}} +{{- if .Values.namespaceOverride -}} +{{- .Values.namespaceOverride -}} +{{- else -}} +{{- .Release.Namespace -}} +{{- end -}} +{{- end -}} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/clusterrole.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/clusterrole.yaml new file mode 100644 index 0000000000..c065f1726c --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/clusterrole.yaml @@ -0,0 +1,77 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: longhorn-role + labels: {{- include "longhorn.labels" . | nindent 4 }} +rules: +- apiGroups: + - apiextensions.k8s.io + resources: + - customresourcedefinitions + verbs: + - "*" +- apiGroups: [""] + resources: ["pods", "events", "persistentvolumes", "persistentvolumeclaims","persistentvolumeclaims/status", "nodes", "proxy/nodes", "pods/log", "secrets", "services", "endpoints", "configmaps", "serviceaccounts"] + verbs: ["*"] +- apiGroups: [""] + resources: ["namespaces"] + verbs: ["get", "list"] +- apiGroups: ["apps"] + resources: ["daemonsets", "statefulsets", "deployments"] + verbs: ["*"] +- apiGroups: ["batch"] + resources: ["jobs", "cronjobs"] + verbs: ["*"] +- apiGroups: ["policy"] + resources: ["poddisruptionbudgets", "podsecuritypolicies"] + verbs: ["*"] +- apiGroups: ["scheduling.k8s.io"] + resources: ["priorityclasses"] + verbs: ["watch", "list"] +- apiGroups: ["storage.k8s.io"] + resources: ["storageclasses", "volumeattachments", "volumeattachments/status", "csinodes", "csidrivers"] + verbs: ["*"] +- apiGroups: ["snapshot.storage.k8s.io"] + resources: ["volumesnapshotclasses", "volumesnapshots", "volumesnapshotcontents", "volumesnapshotcontents/status"] + verbs: ["*"] +- apiGroups: ["longhorn.io"] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", "settings/status", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + {{- if .Values.openshift.enabled }} + "engineimages/finalizers", "nodes/finalizers", "instancemanagers/finalizers", + {{- end }} + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status", "backupbackingimages", "backupbackingimages/status"] + verbs: ["*"] +- apiGroups: ["coordination.k8s.io"] + resources: ["leases"] + verbs: ["*"] +- apiGroups: ["metrics.k8s.io"] + resources: ["pods", "nodes"] + verbs: ["get", "list"] +- apiGroups: ["apiregistration.k8s.io"] + resources: ["apiservices"] + verbs: ["list", "watch"] +- apiGroups: ["admissionregistration.k8s.io"] + resources: ["mutatingwebhookconfigurations", "validatingwebhookconfigurations"] + verbs: ["get", "list", "create", "patch", "delete"] +- apiGroups: ["rbac.authorization.k8s.io"] + resources: ["roles", "rolebindings", "clusterrolebindings", "clusterroles"] + verbs: ["*"] +{{- if .Values.openshift.enabled }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: longhorn-ocp-privileged-role + labels: {{- include "longhorn.labels" . | nindent 4 }} +rules: +- apiGroups: ["security.openshift.io"] + resources: ["securitycontextconstraints"] + resourceNames: ["anyuid", "privileged"] + verbs: ["use"] +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/clusterrolebinding.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/clusterrolebinding.yaml new file mode 100644 index 0000000000..2e34f014ce --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/clusterrolebinding.yaml @@ -0,0 +1,49 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-bind + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: longhorn-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-support-bundle + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: +- kind: ServiceAccount + name: longhorn-support-bundle + namespace: {{ include "release_namespace" . }} +{{- if .Values.openshift.enabled }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-ocp-privileged-bind + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: longhorn-ocp-privileged-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: longhorn-ui-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: default # supportbundle-agent-support-bundle uses default sa + namespace: {{ include "release_namespace" . }} +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/daemonset-sa.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/daemonset-sa.yaml new file mode 100644 index 0000000000..af7c09a409 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/daemonset-sa.yaml @@ -0,0 +1,180 @@ +apiVersion: apps/v1 +kind: DaemonSet +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-manager + name: longhorn-manager + namespace: {{ include "release_namespace" . }} +spec: + selector: + matchLabels: + app: longhorn-manager + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-manager + {{- with .Values.annotations }} + annotations: + {{- toYaml . | nindent 8 }} + {{- end }} + spec: + containers: + - name: longhorn-manager + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + privileged: true + command: + - longhorn-manager + - -d + {{- if eq .Values.longhornManager.log.format "json" }} + - -j + {{- end }} + - daemon + - --engine-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.engine.repository }}:{{ .Values.image.longhorn.engine.tag }}" + - --instance-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.instanceManager.repository }}:{{ .Values.image.longhorn.instanceManager.tag }}" + - --share-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.shareManager.repository }}:{{ .Values.image.longhorn.shareManager.tag }}" + - --backing-image-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.backingImageManager.repository }}:{{ .Values.image.longhorn.backingImageManager.tag }}" + - --support-bundle-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.supportBundleKit.repository }}:{{ .Values.image.longhorn.supportBundleKit.tag }}" + - --manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }}" + - --service-account + - longhorn-service-account + {{- if .Values.preUpgradeChecker.upgradeVersionCheck}} + - --upgrade-version-check + {{- end }} + ports: + - containerPort: 9500 + name: manager + - containerPort: 9501 + name: conversion-wh + - containerPort: 9502 + name: admission-wh + - containerPort: 9503 + name: recov-backend + readinessProbe: + httpGet: + path: /v1/healthz + port: 9501 + scheme: HTTPS + volumeMounts: + - name: boot + mountPath: /host/boot/ + - name: dev + mountPath: /host/dev/ + - name: proc + mountPath: /host/proc/ + - name: longhorn + mountPath: /var/lib/longhorn/ + mountPropagation: Bidirectional + - name: longhorn-grpc-tls + mountPath: /tls-files/ + {{- if .Values.enableGoCoverDir }} + - name: go-cover-dir + mountPath: /go-cover-dir/ + {{- end }} + env: + - name: POD_NAME + valueFrom: + fieldRef: + fieldPath: metadata.name + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: POD_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + {{- if .Values.enableGoCoverDir }} + - name: GOCOVERDIR + value: /go-cover-dir/ + {{- end }} + - name: pre-pull-share-manager-image + imagePullPolicy: {{ .Values.image.pullPolicy }} + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.shareManager.repository }}:{{ .Values.image.longhorn.shareManager.tag }} + command: ["sh", "-c", "echo share-manager image pulled && sleep infinity"] + volumes: + - name: boot + hostPath: + path: /boot/ + - name: dev + hostPath: + path: /dev/ + - name: proc + hostPath: + path: /proc/ + - name: longhorn + hostPath: + path: /var/lib/longhorn/ + {{- if .Values.enableGoCoverDir }} + - name: go-cover-dir + hostPath: + path: /go-cover-dir/ + type: DirectoryOrCreate + {{- end }} + - name: longhorn-grpc-tls + secret: + secretName: longhorn-grpc-tls + optional: true + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} + serviceAccountName: longhorn-service-account + updateStrategy: + rollingUpdate: + maxUnavailable: "100%" +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-manager + name: longhorn-backend + namespace: {{ include "release_namespace" . }} + {{- if .Values.longhornManager.serviceAnnotations }} + annotations: +{{ toYaml .Values.longhornManager.serviceAnnotations | indent 4 }} + {{- end }} +spec: + type: {{ .Values.service.manager.type }} + selector: + app: longhorn-manager + ports: + - name: manager + port: 9500 + targetPort: manager + {{- if .Values.service.manager.nodePort }} + nodePort: {{ .Values.service.manager.nodePort }} + {{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/default-setting.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/default-setting.yaml new file mode 100644 index 0000000000..315cdc6ec9 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/default-setting.yaml @@ -0,0 +1,244 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-default-setting + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +data: + default-setting.yaml: |- + {{- if not (kindIs "invalid" .Values.defaultSettings.backupTarget) }} + backup-target: {{ .Values.defaultSettings.backupTarget }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupTargetCredentialSecret) }} + backup-target-credential-secret: {{ .Values.defaultSettings.backupTargetCredentialSecret }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowRecurringJobWhileVolumeDetached) }} + allow-recurring-job-while-volume-detached: {{ .Values.defaultSettings.allowRecurringJobWhileVolumeDetached }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.createDefaultDiskLabeledNodes) }} + create-default-disk-labeled-nodes: {{ .Values.defaultSettings.createDefaultDiskLabeledNodes }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultDataPath) }} + default-data-path: {{ .Values.defaultSettings.defaultDataPath }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaSoftAntiAffinity) }} + replica-soft-anti-affinity: {{ .Values.defaultSettings.replicaSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaAutoBalance) }} + replica-auto-balance: {{ .Values.defaultSettings.replicaAutoBalance }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageOverProvisioningPercentage) }} + storage-over-provisioning-percentage: {{ .Values.defaultSettings.storageOverProvisioningPercentage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageMinimalAvailablePercentage) }} + storage-minimal-available-percentage: {{ .Values.defaultSettings.storageMinimalAvailablePercentage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageReservedPercentageForDefaultDisk) }} + storage-reserved-percentage-for-default-disk: {{ .Values.defaultSettings.storageReservedPercentageForDefaultDisk }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.upgradeChecker) }} + upgrade-checker: {{ .Values.defaultSettings.upgradeChecker }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultReplicaCount) }} + default-replica-count: {{ .Values.defaultSettings.defaultReplicaCount }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultDataLocality) }} + default-data-locality: {{ .Values.defaultSettings.defaultDataLocality }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultLonghornStaticStorageClass) }} + default-longhorn-static-storage-class: {{ .Values.defaultSettings.defaultLonghornStaticStorageClass }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupstorePollInterval) }} + backupstore-poll-interval: {{ .Values.defaultSettings.backupstorePollInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.failedBackupTTL) }} + failed-backup-ttl: {{ .Values.defaultSettings.failedBackupTTL }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.restoreVolumeRecurringJobs) }} + restore-volume-recurring-jobs: {{ .Values.defaultSettings.restoreVolumeRecurringJobs }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringSuccessfulJobsHistoryLimit) }} + recurring-successful-jobs-history-limit: {{ .Values.defaultSettings.recurringSuccessfulJobsHistoryLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringJobMaxRetention) }} + recurring-job-max-retention: {{ .Values.defaultSettings.recurringJobMaxRetention }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringFailedJobsHistoryLimit) }} + recurring-failed-jobs-history-limit: {{ .Values.defaultSettings.recurringFailedJobsHistoryLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.supportBundleFailedHistoryLimit) }} + support-bundle-failed-history-limit: {{ .Values.defaultSettings.supportBundleFailedHistoryLimit }} + {{- end }} + {{- if or (not (kindIs "invalid" .Values.defaultSettings.taintToleration)) (.Values.global.cattle.windowsCluster.enabled) }} + taint-toleration: {{ $windowsDefaultSettingTaintToleration := list }}{{ $defaultSettingTaintToleration := list -}} + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.defaultSetting.taintToleration -}} + {{- $windowsDefaultSettingTaintToleration = .Values.global.cattle.windowsCluster.defaultSetting.taintToleration -}} + {{- end -}} + {{- if not (kindIs "invalid" .Values.defaultSettings.taintToleration) -}} + {{- $defaultSettingTaintToleration = .Values.defaultSettings.taintToleration -}} + {{- end -}} + {{- $taintToleration := list $windowsDefaultSettingTaintToleration $defaultSettingTaintToleration }}{{ join ";" (compact $taintToleration) -}} + {{- end }} + {{- if or (not (kindIs "invalid" .Values.defaultSettings.systemManagedComponentsNodeSelector)) (.Values.global.cattle.windowsCluster.enabled) }} + system-managed-components-node-selector: {{ $windowsDefaultSettingNodeSelector := list }}{{ $defaultSettingNodeSelector := list -}} + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.defaultSetting.systemManagedComponentsNodeSelector -}} + {{ $windowsDefaultSettingNodeSelector = .Values.global.cattle.windowsCluster.defaultSetting.systemManagedComponentsNodeSelector -}} + {{- end -}} + {{- if not (kindIs "invalid" .Values.defaultSettings.systemManagedComponentsNodeSelector) -}} + {{- $defaultSettingNodeSelector = .Values.defaultSettings.systemManagedComponentsNodeSelector -}} + {{- end -}} + {{- $nodeSelector := list $windowsDefaultSettingNodeSelector $defaultSettingNodeSelector }}{{ join ";" (compact $nodeSelector) -}} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.priorityClass) }} + priority-class: {{ .Values.defaultSettings.priorityClass }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoSalvage) }} + auto-salvage: {{ .Values.defaultSettings.autoSalvage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly) }} + auto-delete-pod-when-volume-detached-unexpectedly: {{ .Values.defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableSchedulingOnCordonedNode) }} + disable-scheduling-on-cordoned-node: {{ .Values.defaultSettings.disableSchedulingOnCordonedNode }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaZoneSoftAntiAffinity) }} + replica-zone-soft-anti-affinity: {{ .Values.defaultSettings.replicaZoneSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaDiskSoftAntiAffinity) }} + replica-disk-soft-anti-affinity: {{ .Values.defaultSettings.replicaDiskSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.nodeDownPodDeletionPolicy) }} + node-down-pod-deletion-policy: {{ .Values.defaultSettings.nodeDownPodDeletionPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.nodeDrainPolicy) }} + node-drain-policy: {{ .Values.defaultSettings.nodeDrainPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.detachManuallyAttachedVolumesWhenCordoned) }} + detach-manually-attached-volumes-when-cordoned: {{ .Values.defaultSettings.detachManuallyAttachedVolumesWhenCordoned }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaReplenishmentWaitInterval) }} + replica-replenishment-wait-interval: {{ .Values.defaultSettings.replicaReplenishmentWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentReplicaRebuildPerNodeLimit) }} + concurrent-replica-rebuild-per-node-limit: {{ .Values.defaultSettings.concurrentReplicaRebuildPerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentVolumeBackupRestorePerNodeLimit) }} + concurrent-volume-backup-restore-per-node-limit: {{ .Values.defaultSettings.concurrentVolumeBackupRestorePerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableRevisionCounter) }} + disable-revision-counter: {{ .Values.defaultSettings.disableRevisionCounter }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.systemManagedPodsImagePullPolicy) }} + system-managed-pods-image-pull-policy: {{ .Values.defaultSettings.systemManagedPodsImagePullPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowVolumeCreationWithDegradedAvailability) }} + allow-volume-creation-with-degraded-availability: {{ .Values.defaultSettings.allowVolumeCreationWithDegradedAvailability }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupSystemGeneratedSnapshot) }} + auto-cleanup-system-generated-snapshot: {{ .Values.defaultSettings.autoCleanupSystemGeneratedSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupRecurringJobBackupSnapshot) }} + auto-cleanup-recurring-job-backup-snapshot: {{ .Values.defaultSettings.autoCleanupRecurringJobBackupSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit) }} + concurrent-automatic-engine-upgrade-per-node-limit: {{ .Values.defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backingImageCleanupWaitInterval) }} + backing-image-cleanup-wait-interval: {{ .Values.defaultSettings.backingImageCleanupWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backingImageRecoveryWaitInterval) }} + backing-image-recovery-wait-interval: {{ .Values.defaultSettings.backingImageRecoveryWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.guaranteedInstanceManagerCPU) }} + guaranteed-instance-manager-cpu: {{ .Values.defaultSettings.guaranteedInstanceManagerCPU }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.kubernetesClusterAutoscalerEnabled) }} + kubernetes-cluster-autoscaler-enabled: {{ .Values.defaultSettings.kubernetesClusterAutoscalerEnabled }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.orphanAutoDeletion) }} + orphan-auto-deletion: {{ .Values.defaultSettings.orphanAutoDeletion }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageNetwork) }} + storage-network: {{ .Values.defaultSettings.storageNetwork }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.deletingConfirmationFlag) }} + deleting-confirmation-flag: {{ .Values.defaultSettings.deletingConfirmationFlag }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.engineReplicaTimeout) }} + engine-replica-timeout: {{ .Values.defaultSettings.engineReplicaTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrity) }} + snapshot-data-integrity: {{ .Values.defaultSettings.snapshotDataIntegrity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation) }} + snapshot-data-integrity-immediate-check-after-snapshot-creation: {{ .Values.defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrityCronjob) }} + snapshot-data-integrity-cronjob: {{ .Values.defaultSettings.snapshotDataIntegrityCronjob }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.removeSnapshotsDuringFilesystemTrim) }} + remove-snapshots-during-filesystem-trim: {{ .Values.defaultSettings.removeSnapshotsDuringFilesystemTrim }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.fastReplicaRebuildEnabled) }} + fast-replica-rebuild-enabled: {{ .Values.defaultSettings.fastReplicaRebuildEnabled }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaFileSyncHttpClientTimeout) }} + replica-file-sync-http-client-timeout: {{ .Values.defaultSettings.replicaFileSyncHttpClientTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.longGRPCTimeOut) }} + long-grpc-timeout: {{ .Values.defaultSettings.longGRPCTimeOut }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.logLevel) }} + log-level: {{ .Values.defaultSettings.logLevel }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupCompressionMethod) }} + backup-compression-method: {{ .Values.defaultSettings.backupCompressionMethod }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupConcurrentLimit) }} + backup-concurrent-limit: {{ .Values.defaultSettings.backupConcurrentLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.restoreConcurrentLimit) }} + restore-concurrent-limit: {{ .Values.defaultSettings.restoreConcurrentLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v1DataEngine) }} + v1-data-engine: {{ .Values.defaultSettings.v1DataEngine }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngine) }} + v2-data-engine: {{ .Values.defaultSettings.v2DataEngine }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineHugepageLimit) }} + v2-data-engine-hugepage-limit: {{ .Values.defaultSettings.v2DataEngineHugepageLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowEmptyNodeSelectorVolume) }} + allow-empty-node-selector-volume: {{ .Values.defaultSettings.allowEmptyNodeSelectorVolume }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowEmptyDiskSelectorVolume) }} + allow-empty-disk-selector-volume: {{ .Values.defaultSettings.allowEmptyDiskSelectorVolume }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowCollectingLonghornUsageMetrics) }} + allow-collecting-longhorn-usage-metrics: {{ .Values.defaultSettings.allowCollectingLonghornUsageMetrics }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableSnapshotPurge) }} + disable-snapshot-purge: {{ .Values.defaultSettings.disableSnapshotPurge }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU) }} + v2-data-engine-guaranteed-instance-manager-cpu: {{ .Values.defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotMaxCount) }} + snapshot-max-count: {{ .Values.defaultSettings.snapshotMaxCount }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineLogLevel) }} + v2-data-engine-log-level: {{ .Values.defaultSettings.v2DataEngineLogLevel }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineLogFlags) }} + v2-data-engine-log-flags: {{ .Values.defaultSettings.v2DataEngineLogFlags }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.freezeFilesystemForSnapshot) }} + freeze-filesystem-for-snapshot: {{ .Values.defaultSettings.freezeFilesystemForSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupSnapshotWhenDeleteBackup) }} + auto-cleanup-when-delete-backup: {{ .Values.defaultSettings.autoCleanupSnapshotWhenDeleteBackup }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.rwxVolumeFastFailover) }} + rwx-volume-fast-failover: {{ .Values.defaultSettings.rwxVolumeFastFailover}} + {{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/deployment-driver.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/deployment-driver.yaml new file mode 100644 index 0000000000..3ac582dcbc --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/deployment-driver.yaml @@ -0,0 +1,132 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: longhorn-driver-deployer + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + replicas: 1 + selector: + matchLabels: + app: longhorn-driver-deployer + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-driver-deployer + spec: + initContainers: + - name: wait-longhorn-manager + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + command: ['sh', '-c', 'while [ $(curl -m 1 -s -o /dev/null -w "%{http_code}" http://longhorn-backend:9500/v1) != "200" ]; do echo waiting; sleep 2; done'] + containers: + - name: longhorn-driver-deployer + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - -d + - deploy-driver + - --manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }}" + - --manager-url + - http://longhorn-backend:9500/v1 + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + - name: SERVICE_ACCOUNT + valueFrom: + fieldRef: + fieldPath: spec.serviceAccountName + {{- if .Values.csi.kubeletRootDir }} + - name: KUBELET_ROOT_DIR + value: {{ .Values.csi.kubeletRootDir }} + {{- end }} + {{- if and .Values.image.csi.attacher.repository .Values.image.csi.attacher.tag }} + - name: CSI_ATTACHER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.attacher.repository }}:{{ .Values.image.csi.attacher.tag }}" + {{- end }} + {{- if and .Values.image.csi.provisioner.repository .Values.image.csi.provisioner.tag }} + - name: CSI_PROVISIONER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.provisioner.repository }}:{{ .Values.image.csi.provisioner.tag }}" + {{- end }} + {{- if and .Values.image.csi.nodeDriverRegistrar.repository .Values.image.csi.nodeDriverRegistrar.tag }} + - name: CSI_NODE_DRIVER_REGISTRAR_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.nodeDriverRegistrar.repository }}:{{ .Values.image.csi.nodeDriverRegistrar.tag }}" + {{- end }} + {{- if and .Values.image.csi.resizer.repository .Values.image.csi.resizer.tag }} + - name: CSI_RESIZER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.resizer.repository }}:{{ .Values.image.csi.resizer.tag }}" + {{- end }} + {{- if and .Values.image.csi.snapshotter.repository .Values.image.csi.snapshotter.tag }} + - name: CSI_SNAPSHOTTER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.snapshotter.repository }}:{{ .Values.image.csi.snapshotter.tag }}" + {{- end }} + {{- if and .Values.image.csi.livenessProbe.repository .Values.image.csi.livenessProbe.tag }} + - name: CSI_LIVENESS_PROBE_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.livenessProbe.repository }}:{{ .Values.image.csi.livenessProbe.tag }}" + {{- end }} + {{- if .Values.csi.attacherReplicaCount }} + - name: CSI_ATTACHER_REPLICA_COUNT + value: {{ .Values.csi.attacherReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.provisionerReplicaCount }} + - name: CSI_PROVISIONER_REPLICA_COUNT + value: {{ .Values.csi.provisionerReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.resizerReplicaCount }} + - name: CSI_RESIZER_REPLICA_COUNT + value: {{ .Values.csi.resizerReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.snapshotterReplicaCount }} + - name: CSI_SNAPSHOTTER_REPLICA_COUNT + value: {{ .Values.csi.snapshotterReplicaCount | quote }} + {{- end }} + {{- if .Values.enableGoCoverDir }} + - name: GOCOVERDIR + value: /go-cover-dir/ + volumeMounts: + - name: go-cover-dir + mountPath: /go-cover-dir/ + {{- end }} + + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornDriver.priorityClass }} + priorityClassName: {{ .Values.longhornDriver.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornDriver.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornDriver.tolerations }} +{{ default .Values.global.tolerations .Values.longhornDriver.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornDriver.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornDriver.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornDriver.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} + serviceAccountName: longhorn-service-account + securityContext: + runAsUser: 0 + {{- if .Values.enableGoCoverDir }} + volumes: + - name: go-cover-dir + hostPath: + path: /go-cover-dir/ + type: DirectoryOrCreate + {{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/deployment-ui.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/deployment-ui.yaml new file mode 100644 index 0000000000..e4f3e0f8f7 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/deployment-ui.yaml @@ -0,0 +1,186 @@ +{{- if .Values.openshift.enabled }} +{{- if .Values.openshift.ui.route }} +# https://github.com/openshift/oauth-proxy/blob/master/contrib/sidecar.yaml +# Create a proxy service account and ensure it will use the route "proxy" +# Create a secure connection to the proxy via a route +apiVersion: route.openshift.io/v1 +kind: Route +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: {{ .Values.openshift.ui.route }} + namespace: {{ include "release_namespace" . }} +spec: + to: + kind: Service + name: longhorn-ui + tls: + termination: reencrypt +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: longhorn-ui + namespace: {{ include "release_namespace" . }} + annotations: + service.alpha.openshift.io/serving-cert-secret-name: longhorn-ui-tls +spec: + ports: + - name: longhorn-ui + port: {{ .Values.openshift.ui.port | default 443 }} + targetPort: {{ .Values.openshift.ui.proxy | default 8443 }} + selector: + app: longhorn-ui +--- +{{- end }} +{{- end }} +apiVersion: apps/v1 +kind: Deployment +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: longhorn-ui + namespace: {{ include "release_namespace" . }} +spec: + replicas: {{ .Values.longhornUI.replicas }} + selector: + matchLabels: + app: longhorn-ui + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-ui + spec: + serviceAccountName: longhorn-ui-service-account + affinity: + podAntiAffinity: + preferredDuringSchedulingIgnoredDuringExecution: + - weight: 1 + podAffinityTerm: + labelSelector: + matchExpressions: + - key: app + operator: In + values: + - longhorn-ui + topologyKey: kubernetes.io/hostname + containers: + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + - name: oauth-proxy + {{- if .Values.image.openshift.oauthProxy.repository }} + image: {{ template "registry_url" . }}{{ .Values.image.openshift.oauthProxy.repository }}:{{ .Values.image.openshift.oauthProxy.tag }} + {{- else }} + image: "" + {{- end }} + imagePullPolicy: IfNotPresent + ports: + - containerPort: {{ .Values.openshift.ui.proxy | default 8443 }} + name: public + args: + - --https-address=:{{ .Values.openshift.ui.proxy | default 8443 }} + - --provider=openshift + - --openshift-service-account=longhorn-ui-service-account + - --upstream=http://localhost:8000 + - --tls-cert=/etc/tls/private/tls.crt + - --tls-key=/etc/tls/private/tls.key + - --cookie-secret=SECRET + - --openshift-sar={"namespace":"{{ include "release_namespace" . }}","group":"longhorn.io","resource":"setting","verb":"delete"} + volumeMounts: + - mountPath: /etc/tls/private + name: longhorn-ui-tls + {{- end }} + {{- end }} + - name: longhorn-ui + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.ui.repository }}:{{ .Values.image.longhorn.ui.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + volumeMounts: + - name : nginx-cache + mountPath: /var/cache/nginx/ + - name : nginx-config + mountPath: /var/config/nginx/ + - name: var-run + mountPath: /var/run/ + ports: + - containerPort: 8000 + name: http + env: + - name: LONGHORN_MANAGER_IP + value: "http://longhorn-backend:9500" + - name: LONGHORN_UI_PORT + value: "8000" + volumes: + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + - name: longhorn-ui-tls + secret: + secretName: longhorn-ui-tls + {{- end }} + {{- end }} + - emptyDir: {} + name: nginx-cache + - emptyDir: {} + name: nginx-config + - emptyDir: {} + name: var-run + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornUI.priorityClass }} + priorityClassName: {{ .Values.longhornUI.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornUI.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornUI.tolerations }} +{{ default .Values.global.tolerations .Values.longhornUI.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornUI.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornUI.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornUI.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} +--- +kind: Service +apiVersion: v1 +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + {{- if eq .Values.service.ui.type "Rancher-Proxy" }} + kubernetes.io/cluster-service: "true" + {{- end }} + name: longhorn-frontend + namespace: {{ include "release_namespace" . }} +spec: + {{- if eq .Values.service.ui.type "Rancher-Proxy" }} + type: ClusterIP + {{- else }} + type: {{ .Values.service.ui.type }} + {{- end }} + {{- if and .Values.service.ui.loadBalancerIP (eq .Values.service.ui.type "LoadBalancer") }} + loadBalancerIP: {{ .Values.service.ui.loadBalancerIP }} + {{- end }} + {{- if and (eq .Values.service.ui.type "LoadBalancer") .Values.service.ui.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.service.ui.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + selector: + app: longhorn-ui + ports: + - name: http + port: 80 + targetPort: http + {{- if .Values.service.ui.nodePort }} + nodePort: {{ .Values.service.ui.nodePort }} + {{- else }} + nodePort: null + {{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/ingress.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/ingress.yaml new file mode 100644 index 0000000000..61175e827b --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/ingress.yaml @@ -0,0 +1,37 @@ +{{- if .Values.ingress.enabled }} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: longhorn-ingress + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ingress + annotations: + {{- if .Values.ingress.secureBackends }} + ingress.kubernetes.io/secure-backends: "true" + {{- end }} + {{- range $key, $value := .Values.ingress.annotations }} + {{ $key }}: {{ $value | quote }} + {{- end }} +spec: + {{- if .Values.ingress.ingressClassName }} + ingressClassName: {{ .Values.ingress.ingressClassName }} + {{- end }} + rules: + - host: {{ .Values.ingress.host }} + http: + paths: + - path: {{ default "" .Values.ingress.path }} + pathType: {{ default "ImplementationSpecific" .Values.ingress.pathType }} + backend: + service: + name: longhorn-frontend + port: + number: 80 +{{- if .Values.ingress.tls }} + tls: + - hosts: + - {{ .Values.ingress.host }} + secretName: {{ .Values.ingress.tlsSecret }} +{{- end }} +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/backing-image-data-source-network-policy.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/backing-image-data-source-network-policy.yaml new file mode 100644 index 0000000000..7204d63caa --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/backing-image-data-source-network-policy.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: backing-image-data-source + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/backing-image-manager-network-policy.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/backing-image-manager-network-policy.yaml new file mode 100644 index 0000000000..119ebf08a1 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/backing-image-manager-network-policy.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: backing-image-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/instance-manager-networking.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/instance-manager-networking.yaml new file mode 100644 index 0000000000..332aa2c2fe --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/instance-manager-networking.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: instance-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: instance-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/manager-network-policy.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/manager-network-policy.yaml new file mode 100644 index 0000000000..6f94029a53 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/manager-network-policy.yaml @@ -0,0 +1,35 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + app: longhorn-ui + - podSelector: + matchLabels: + app: longhorn-csi-plugin + - podSelector: + matchLabels: + longhorn.io/managed-by: longhorn-manager + matchExpressions: + - { key: recurring-job.longhorn.io, operator: Exists } + - podSelector: + matchExpressions: + - { key: longhorn.io/job-task, operator: Exists } + - podSelector: + matchLabels: + app: longhorn-driver-deployer +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/recovery-backend-network-policy.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/recovery-backend-network-policy.yaml new file mode 100644 index 0000000000..37bf5f9bcf --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/recovery-backend-network-policy.yaml @@ -0,0 +1,17 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-recovery-backend + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/recovery-backend: longhorn-recovery-backend + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9503 +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/ui-frontend-network-policy.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/ui-frontend-network-policy.yaml new file mode 100644 index 0000000000..6f37065980 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/ui-frontend-network-policy.yaml @@ -0,0 +1,46 @@ +{{- if and .Values.networkPolicies.enabled .Values.ingress.enabled (not (eq .Values.networkPolicies.type "")) }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-ui-frontend + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-ui + policyTypes: + - Ingress + ingress: + - from: + {{- if eq .Values.networkPolicies.type "rke1"}} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress-nginx + podSelector: + matchLabels: + app.kubernetes.io/component: controller + app.kubernetes.io/instance: ingress-nginx + app.kubernetes.io/name: ingress-nginx + {{- else if eq .Values.networkPolicies.type "rke2" }} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + podSelector: + matchLabels: + app.kubernetes.io/component: controller + app.kubernetes.io/instance: rke2-ingress-nginx + app.kubernetes.io/name: rke2-ingress-nginx + {{- else if eq .Values.networkPolicies.type "k3s" }} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + podSelector: + matchLabels: + app.kubernetes.io/name: traefik + ports: + - port: 8000 + protocol: TCP + - port: 80 + protocol: TCP + {{- end }} +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/webhook-network-policy.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/webhook-network-policy.yaml new file mode 100644 index 0000000000..3812e0ffa3 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/network-policies/webhook-network-policy.yaml @@ -0,0 +1,33 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/conversion-webhook: longhorn-conversion-webhook + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9501 +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-admission-webhook + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/admission-webhook: longhorn-admission-webhook + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9502 +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/postupgrade-job.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/postupgrade-job.yaml new file mode 100644 index 0000000000..56efd38e9b --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/postupgrade-job.yaml @@ -0,0 +1,56 @@ +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": post-upgrade + "helm.sh/hook-delete-policy": hook-succeeded,before-hook-creation + name: longhorn-post-upgrade + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-post-upgrade + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-post-upgrade + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - post-upgrade + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: OnFailure + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/preupgrade-job.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/preupgrade-job.yaml new file mode 100644 index 0000000000..9f7a8a6aa6 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/preupgrade-job.yaml @@ -0,0 +1,64 @@ +{{- if and .Values.preUpgradeChecker.jobEnabled .Values.preUpgradeChecker.upgradeVersionCheck}} +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": pre-upgrade + "helm.sh/hook-delete-policy": hook-succeeded,before-hook-creation,hook-failed + name: longhorn-pre-upgrade + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-pre-upgrade + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-pre-upgrade + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + privileged: true + command: + - longhorn-manager + - pre-upgrade + volumeMounts: + - name: proc + mountPath: /host/proc/ + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + volumes: + - name: proc + hostPath: + path: /proc/ + restartPolicy: OnFailure + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/priorityclass.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/priorityclass.yaml new file mode 100644 index 0000000000..208adc84a2 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/priorityclass.yaml @@ -0,0 +1,9 @@ +apiVersion: scheduling.k8s.io/v1 +kind: PriorityClass +metadata: + name: "longhorn-critical" + labels: {{- include "longhorn.labels" . | nindent 4 }} +description: "Ensure Longhorn pods have the highest priority to prevent any unexpected eviction by the Kubernetes scheduler under node pressure" +globalDefault: false +preemptionPolicy: PreemptLowerPriority +value: 1000000000 diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/psp.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/psp.yaml new file mode 100644 index 0000000000..a2dfc05bef --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/psp.yaml @@ -0,0 +1,66 @@ +{{- if .Values.enablePSP }} +apiVersion: policy/v1beta1 +kind: PodSecurityPolicy +metadata: + name: longhorn-psp + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + privileged: true + allowPrivilegeEscalation: true + requiredDropCapabilities: + - NET_RAW + allowedCapabilities: + - SYS_ADMIN + hostNetwork: false + hostIPC: false + hostPID: true + runAsUser: + rule: RunAsAny + seLinux: + rule: RunAsAny + fsGroup: + rule: RunAsAny + supplementalGroups: + rule: RunAsAny + volumes: + - configMap + - downwardAPI + - emptyDir + - secret + - projected + - hostPath +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: longhorn-psp-role + labels: {{- include "longhorn.labels" . | nindent 4 }} + namespace: {{ include "release_namespace" . }} +rules: +- apiGroups: + - policy + resources: + - podsecuritypolicies + verbs: + - use + resourceNames: + - longhorn-psp +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: longhorn-psp-binding + labels: {{- include "longhorn.labels" . | nindent 4 }} + namespace: {{ include "release_namespace" . }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: longhorn-psp-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: default + namespace: {{ include "release_namespace" . }} +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/registry-secret.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/registry-secret.yaml new file mode 100644 index 0000000000..3c6b1dc510 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/registry-secret.yaml @@ -0,0 +1,13 @@ +{{- if .Values.privateRegistry.createSecret }} +{{- if .Values.privateRegistry.registrySecret }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .Values.privateRegistry.registrySecret }} + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +type: kubernetes.io/dockerconfigjson +data: + .dockerconfigjson: {{ template "secret" . }} +{{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/serviceaccount.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/serviceaccount.yaml new file mode 100644 index 0000000000..b0d6dd505b --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/serviceaccount.yaml @@ -0,0 +1,40 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-ui-service-account + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + {{- if not .Values.serviceAccount.annotations }} + annotations: + {{- end }} + serviceaccounts.openshift.io/oauth-redirectreference.primary: '{"kind":"OAuthRedirectReference","apiVersion":"v1","reference":{"kind":"Route","name":"longhorn-ui"}}' + {{- end }} + {{- end }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-support-bundle + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/servicemonitor.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/servicemonitor.yaml new file mode 100644 index 0000000000..3f32961332 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/servicemonitor.yaml @@ -0,0 +1,40 @@ +{{- if .Values.metrics.serviceMonitor.enabled -}} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: longhorn-prometheus-servicemonitor + namespace: {{ include "release_namespace" . }} + labels: + {{- include "longhorn.labels" . | nindent 4 }} + name: longhorn-prometheus-servicemonitor + {{- with .Values.metrics.serviceMonitor.additionalLabels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: + app: longhorn-manager + namespaceSelector: + matchNames: + - {{ include "release_namespace" . }} + endpoints: + - port: manager + {{- with .Values.metrics.serviceMonitor.interval }} + interval: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.relabelings }} + relabelings: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.metricRelabelings }} + metricRelabelings: + {{- toYaml . | nindent 8 }} + {{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/services.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/services.yaml new file mode 100644 index 0000000000..4c8c6bc687 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/services.yaml @@ -0,0 +1,47 @@ +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-conversion-webhook + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + longhorn.io/conversion-webhook: longhorn-conversion-webhook + ports: + - name: conversion-webhook + port: 9501 + targetPort: conversion-wh +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-admission-webhook + name: longhorn-admission-webhook + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + longhorn.io/admission-webhook: longhorn-admission-webhook + ports: + - name: admission-webhook + port: 9502 + targetPort: admission-wh +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-recovery-backend + name: longhorn-recovery-backend + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + longhorn.io/recovery-backend: longhorn-recovery-backend + ports: + - name: recovery-backend + port: 9503 + targetPort: recov-backend diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/storageclass.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/storageclass.yaml new file mode 100644 index 0000000000..884d38d5f3 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/storageclass.yaml @@ -0,0 +1,57 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-storageclass + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +data: + storageclass.yaml: | + kind: StorageClass + apiVersion: storage.k8s.io/v1 + metadata: + name: longhorn + annotations: + storageclass.kubernetes.io/is-default-class: {{ .Values.persistence.defaultClass | quote }} + provisioner: driver.longhorn.io + allowVolumeExpansion: true + reclaimPolicy: "{{ .Values.persistence.reclaimPolicy }}" + volumeBindingMode: Immediate + parameters: + numberOfReplicas: "{{ .Values.persistence.defaultClassReplicaCount }}" + staleReplicaTimeout: "30" + fromBackup: "" + {{- if .Values.persistence.defaultFsType }} + fsType: "{{ .Values.persistence.defaultFsType }}" + {{- end }} + {{- if .Values.persistence.defaultMkfsParams }} + mkfsParams: "{{ .Values.persistence.defaultMkfsParams }}" + {{- end }} + {{- if .Values.persistence.migratable }} + migratable: "{{ .Values.persistence.migratable }}" + {{- end }} + {{- if .Values.persistence.nfsOptions }} + nfsOptions: "{{ .Values.persistence.nfsOptions }}" + {{- end }} + {{- if .Values.persistence.backingImage.enable }} + backingImage: {{ .Values.persistence.backingImage.name }} + backingImageDataSourceType: {{ .Values.persistence.backingImage.dataSourceType }} + backingImageDataSourceParameters: {{ .Values.persistence.backingImage.dataSourceParameters }} + backingImageChecksum: {{ .Values.persistence.backingImage.expectedChecksum }} + {{- end }} + {{- if .Values.persistence.recurringJobSelector.enable }} + recurringJobSelector: '{{ .Values.persistence.recurringJobSelector.jobList }}' + {{- end }} + dataLocality: {{ .Values.persistence.defaultDataLocality | quote }} + {{- if .Values.persistence.defaultDiskSelector.enable }} + diskSelector: "{{ .Values.persistence.defaultDiskSelector.selector }}" + {{- end }} + {{- if .Values.persistence.defaultNodeSelector.enable }} + nodeSelector: "{{ .Values.persistence.defaultNodeSelector.selector }}" + {{- end }} + {{- if .Values.persistence.removeSnapshotsDuringFilesystemTrim }} + unmapMarkSnapChainRemoved: "{{ .Values.persistence.removeSnapshotsDuringFilesystemTrim }}" + {{- end }} + {{- if .Values.persistence.disableRevisionCounter }} + disableRevisionCounter: "{{ .Values.persistence.disableRevisionCounter }}" + dataEngine: "{{ .Values.persistence.dataEngine }}" + {{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/tls-secrets.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/tls-secrets.yaml new file mode 100644 index 0000000000..74c43426de --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/tls-secrets.yaml @@ -0,0 +1,16 @@ +{{- if .Values.ingress.enabled }} +{{- range .Values.ingress.secrets }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .name }} + namespace: {{ include "release_namespace" $ }} + labels: {{- include "longhorn.labels" $ | nindent 4 }} + app: longhorn +type: kubernetes.io/tls +data: + tls.crt: {{ .certificate | b64enc }} + tls.key: {{ .key | b64enc }} +--- +{{- end }} +{{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/uninstall-job.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/uninstall-job.yaml new file mode 100644 index 0000000000..1ab46207c3 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/uninstall-job.yaml @@ -0,0 +1,57 @@ +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": pre-delete + "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded + name: longhorn-uninstall + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-uninstall + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-uninstall + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - uninstall + - --force + env: + - name: LONGHORN_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: Never + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/userroles.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/userroles.yaml new file mode 100644 index 0000000000..57a68e130c --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/userroles.yaml @@ -0,0 +1,53 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-admin" + labels: + rbac.authorization.k8s.io/aggregate-to-admin: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", "settings/status", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "*" ] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-edit" + labels: + rbac.authorization.k8s.io/aggregate-to-edit: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", "settings/status", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "*" ] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-view" + labels: + rbac.authorization.k8s.io/aggregate-to-view: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", "settings/status", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "get", "list", "watch" ] diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/validate-install-crd.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/validate-install-crd.yaml new file mode 100644 index 0000000000..7bf81816d0 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/validate-install-crd.yaml @@ -0,0 +1,35 @@ +#{{- if gt (len (lookup "rbac.authorization.k8s.io/v1" "ClusterRole" "" "")) 0 -}} +# {{- $found := dict -}} +# {{- set $found "longhorn.io/v1beta1/BackingImageDataSource" false -}} +# {{- set $found "longhorn.io/v1beta1/BackingImageManager" false -}} +# {{- set $found "longhorn.io/v1beta1/BackingImage" false -}} +# {{- set $found "longhorn.io/v1beta2/BackupBackingImage" false -}} +# {{- set $found "longhorn.io/v1beta1/Backup" false -}} +# {{- set $found "longhorn.io/v1beta1/BackupTarget" false -}} +# {{- set $found "longhorn.io/v1beta1/BackupVolume" false -}} +# {{- set $found "longhorn.io/v1beta1/EngineImage" false -}} +# {{- set $found "longhorn.io/v1beta1/Engine" false -}} +# {{- set $found "longhorn.io/v1beta1/InstanceManager" false -}} +# {{- set $found "longhorn.io/v1beta1/Node" false -}} +# {{- set $found "longhorn.io/v1beta2/Orphan" false -}} +# {{- set $found "longhorn.io/v1beta1/RecurringJob" false -}} +# {{- set $found "longhorn.io/v1beta1/Replica" false -}} +# {{- set $found "longhorn.io/v1beta1/Setting" false -}} +# {{- set $found "longhorn.io/v1beta1/ShareManager" false -}} +# {{- set $found "longhorn.io/v1beta2/Snapshot" false -}} +# {{- set $found "longhorn.io/v1beta2/SupportBundle" false -}} +# {{- set $found "longhorn.io/v1beta2/SystemBackup" false -}} +# {{- set $found "longhorn.io/v1beta2/SystemRestore" false -}} +# {{- set $found "longhorn.io/v1beta2/VolumeAttachment" false -}} +# {{- set $found "longhorn.io/v1beta1/Volume" false -}} +# {{- range .Capabilities.APIVersions -}} +# {{- if hasKey $found (toString .) -}} +# {{- set $found (toString .) true -}} +# {{- end -}} +# {{- end -}} +# {{- range $_, $exists := $found -}} +# {{- if (eq $exists false) -}} +# {{- required "Required CRDs are missing. Please install the corresponding CRD chart before installing this chart." "" -}} +# {{- end -}} +# {{- end -}} +#{{- end -}} diff --git a/charts/longhorn/105.1.0+up1.7.2/templates/validate-psp-install.yaml b/charts/longhorn/105.1.0+up1.7.2/templates/validate-psp-install.yaml new file mode 100644 index 0000000000..0df98e3657 --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/templates/validate-psp-install.yaml @@ -0,0 +1,7 @@ +#{{- if gt (len (lookup "rbac.authorization.k8s.io/v1" "ClusterRole" "" "")) 0 -}} +#{{- if .Values.enablePSP }} +#{{- if not (.Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy") }} +#{{- fail "The target cluster does not have the PodSecurityPolicy API resource. Please disable PSPs in this chart before proceeding." -}} +#{{- end }} +#{{- end }} +#{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.1.0+up1.7.2/values.yaml b/charts/longhorn/105.1.0+up1.7.2/values.yaml new file mode 100644 index 0000000000..1fabadb85a --- /dev/null +++ b/charts/longhorn/105.1.0+up1.7.2/values.yaml @@ -0,0 +1,526 @@ +# Default values for longhorn. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. +global: + # -- Toleration for nodes allowed to run user-deployed components such as Longhorn Manager, Longhorn UI, and Longhorn Driver Deployer. + tolerations: [] + # -- Node selector for nodes allowed to run user-deployed components such as Longhorn Manager, Longhorn UI, and Longhorn Driver Deployer. + nodeSelector: {} + cattle: + # -- Default system registry. + systemDefaultRegistry: "" + windowsCluster: + # -- Setting that allows Longhorn to run on a Rancher Windows cluster. + enabled: false + # -- Toleration for Linux nodes that can run user-deployed Longhorn components. + tolerations: + - key: "cattle.io/os" + value: "linux" + effect: "NoSchedule" + operator: "Equal" + # -- Node selector for Linux nodes that can run user-deployed Longhorn components. + nodeSelector: + kubernetes.io/os: "linux" + defaultSetting: + # -- Toleration for system-managed Longhorn components. + taintToleration: cattle.io/os=linux:NoSchedule + # -- Node selector for system-managed Longhorn components. + systemManagedComponentsNodeSelector: kubernetes.io/os:linux + +networkPolicies: + # -- Setting that allows you to enable network policies that control access to Longhorn pods. + enabled: false + # -- Distribution that determines the policy for allowing access for an ingress. (Options: "k3s", "rke2", "rke1") + type: "k3s" + +image: + longhorn: + engine: + # -- Repository for the Longhorn Engine image. + repository: rancher/mirrored-longhornio-longhorn-engine + # -- Tag for the Longhorn Engine image. + tag: v1.7.2 + manager: + # -- Repository for the Longhorn Manager image. + repository: rancher/mirrored-longhornio-longhorn-manager + # -- Tag for the Longhorn Manager image. + tag: v1.7.2 + ui: + # -- Repository for the Longhorn UI image. + repository: rancher/mirrored-longhornio-longhorn-ui + # -- Tag for the Longhorn UI image. + tag: v1.7.2 + instanceManager: + # -- Repository for the Longhorn Instance Manager image. + repository: rancher/mirrored-longhornio-longhorn-instance-manager + # -- Tag for the Longhorn Instance Manager image. + tag: v1.7.2 + shareManager: + # -- Repository for the Longhorn Share Manager image. + repository: rancher/mirrored-longhornio-longhorn-share-manager + # -- Tag for the Longhorn Share Manager image. + tag: v1.7.2 + backingImageManager: + # -- Repository for the Backing Image Manager image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-backing-image-manager + # -- Tag for the Backing Image Manager image. When unspecified, Longhorn uses the default value. + tag: v1.7.2 + supportBundleKit: + # -- Repository for the Longhorn Support Bundle Manager image. + repository: rancher/mirrored-longhornio-support-bundle-kit + # -- Tag for the Longhorn Support Bundle Manager image. + tag: v0.0.45 + csi: + attacher: + # -- Repository for the CSI attacher image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-attacher + # -- Tag for the CSI attacher image. When unspecified, Longhorn uses the default value. + tag: v4.7.0 + provisioner: + # -- Repository for the CSI Provisioner image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-provisioner + # -- Tag for the CSI Provisioner image. When unspecified, Longhorn uses the default value. + tag: v4.0.1-20241007 + nodeDriverRegistrar: + # -- Repository for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-node-driver-registrar + # -- Tag for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value. + tag: v2.12.0 + resizer: + # -- Repository for the CSI Resizer image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-resizer + # -- Tag for the CSI Resizer image. When unspecified, Longhorn uses the default value. + tag: v1.12.0 + snapshotter: + # -- Repository for the CSI Snapshotter image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-snapshotter + # -- Tag for the CSI Snapshotter image. When unspecified, Longhorn uses the default value. + tag: v7.0.2-20241007 + livenessProbe: + # -- Repository for the CSI liveness probe image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-livenessprobe + # -- Tag for the CSI liveness probe image. When unspecified, Longhorn uses the default value. + tag: v2.14.0 + openshift: + oauthProxy: + # -- Repository for the OAuth Proxy image. Specify the upstream image (for example, "quay.io/openshift/origin-oauth-proxy"). This setting applies only to OpenShift users. + repository: "" + # -- Tag for the OAuth Proxy image. Specify OCP/OKD version 4.1 or later (including version 4.15, which is available at quay.io/openshift/origin-oauth-proxy:4.15). This setting applies only to OpenShift users. + tag: "" + # -- Image pull policy that applies to all user-deployed Longhorn components, such as Longhorn Manager, Longhorn driver, and Longhorn UI. + pullPolicy: IfNotPresent + +service: + ui: + # -- Service type for Longhorn UI. (Options: "ClusterIP", "NodePort", "LoadBalancer", "Rancher-Proxy") + type: ClusterIP + # -- NodePort port number for Longhorn UI. When unspecified, Longhorn selects a free port between 30000 and 32767. + nodePort: null + manager: + # -- Service type for Longhorn Manager. + type: ClusterIP + # -- NodePort port number for Longhorn Manager. When unspecified, Longhorn selects a free port between 30000 and 32767. + nodePort: "" + +persistence: + # -- Setting that allows you to specify the default Longhorn StorageClass. + defaultClass: true + # -- Filesystem type of the default Longhorn StorageClass. + defaultFsType: ext4 + # -- mkfs parameters of the default Longhorn StorageClass. + defaultMkfsParams: "" + # -- Replica count of the default Longhorn StorageClass. + defaultClassReplicaCount: 3 + # -- Data locality of the default Longhorn StorageClass. (Options: "disabled", "best-effort") + defaultDataLocality: disabled + # -- Reclaim policy that provides instructions for handling of a volume after its claim is released. (Options: "Retain", "Delete") + reclaimPolicy: Delete + # -- Setting that allows you to enable live migration of a Longhorn volume from one node to another. + migratable: false + # -- Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the volume-head-xxx.img file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. + disableRevisionCounter: "true" + # -- Set NFS mount options for Longhorn StorageClass for RWX volumes + nfsOptions: "" + recurringJobSelector: + # -- Setting that allows you to enable the recurring job selector for a Longhorn StorageClass. + enable: false + # -- Recurring job selector for a Longhorn StorageClass. Ensure that quotes are used correctly when specifying job parameters. (Example: `[{"name":"backup", "isGroup":true}]`) + jobList: [] + backingImage: + # -- Setting that allows you to use a backing image in a Longhorn StorageClass. + enable: false + # -- Backing image to be used for creating and restoring volumes in a Longhorn StorageClass. When no backing images are available, specify the data source type and parameters that Longhorn can use to create a backing image. + name: ~ + # -- Data source type of a backing image used in a Longhorn StorageClass. + # If the backing image exists in the cluster, Longhorn uses this setting to verify the image. + # If the backing image does not exist, Longhorn creates one using the specified data source type. + dataSourceType: ~ + # -- Data source parameters of a backing image used in a Longhorn StorageClass. + # You can specify a JSON string of a map. (Example: `'{\"url\":\"https://backing-image-example.s3-region.amazonaws.com/test-backing-image\"}'`) + dataSourceParameters: ~ + # -- Expected SHA-512 checksum of a backing image used in a Longhorn StorageClass. + expectedChecksum: ~ + defaultDiskSelector: + # -- Setting that allows you to enable the disk selector for the default Longhorn StorageClass. + enable: false + # -- Disk selector for the default Longhorn StorageClass. Longhorn uses only disks with the specified tags for storing volume data. (Examples: "nvme,sata") + selector: "" + defaultNodeSelector: + # -- Setting that allows you to enable the node selector for the default Longhorn StorageClass. + enable: false + # -- Node selector for the default Longhorn StorageClass. Longhorn uses only nodes with the specified tags for storing volume data. (Examples: "storage,fast") + selector: "" + # -- Setting that allows you to enable automatic snapshot removal during filesystem trim for a Longhorn StorageClass. (Options: "ignored", "enabled", "disabled") + removeSnapshotsDuringFilesystemTrim: ignored + # -- Setting that allows you to specify the data engine version for the default Longhorn StorageClass. (Options: "v1", "v2") + dataEngine: v1 + +preUpgradeChecker: + # -- Setting that allows Longhorn to perform pre-upgrade checks. Disable this setting when installing Longhorn using Argo CD or other GitOps solutions. + jobEnabled: true + # -- Setting that allows Longhorn to perform upgrade version checks after starting the Longhorn Manager DaemonSet Pods. Disabling this setting also disables `preUpgradeChecker.jobEnabled`. Longhorn recommends keeping this setting enabled. + upgradeVersionCheck: true + +csi: + # -- kubelet root directory. When unspecified, Longhorn uses the default value. + kubeletRootDir: ~ + # -- Replica count of the CSI Attacher. When unspecified, Longhorn uses the default value ("3"). + attacherReplicaCount: ~ + # -- Replica count of the CSI Provisioner. When unspecified, Longhorn uses the default value ("3"). + provisionerReplicaCount: ~ + # -- Replica count of the CSI Resizer. When unspecified, Longhorn uses the default value ("3"). + resizerReplicaCount: ~ + # -- Replica count of the CSI Snapshotter. When unspecified, Longhorn uses the default value ("3"). + snapshotterReplicaCount: ~ + +defaultSettings: + # -- Endpoint used to access the backupstore. (Options: "NFS", "CIFS", "AWS", "GCP", "AZURE") + backupTarget: ~ + # -- Name of the Kubernetes secret associated with the backup target. + backupTargetCredentialSecret: ~ + # -- Setting that allows Longhorn to automatically attach a volume and create snapshots or backups when recurring jobs are run. + allowRecurringJobWhileVolumeDetached: ~ + # -- Setting that allows Longhorn to automatically create a default disk only on nodes with the label "node.longhorn.io/create-default-disk=true" (if no other disks exist). When this setting is disabled, Longhorn creates a default disk on each node that is added to the cluster. + createDefaultDiskLabeledNodes: ~ + # -- Default path for storing data on a host. The default value is "/var/lib/longhorn/". + defaultDataPath: ~ + # -- Default data locality. A Longhorn volume has data locality if a local replica of the volume exists on the same node as the pod that is using the volume. + defaultDataLocality: ~ + # -- Setting that allows scheduling on nodes with healthy replicas of the same volume. This setting is disabled by default. + replicaSoftAntiAffinity: ~ + # -- Setting that automatically rebalances replicas when an available node is discovered. + replicaAutoBalance: ~ + # -- Percentage of storage that can be allocated relative to hard drive capacity. The default value is "100". + storageOverProvisioningPercentage: ~ + # -- Percentage of minimum available disk capacity. When the minimum available capacity exceeds the total available capacity, the disk becomes unschedulable until more space is made available for use. The default value is "25". + storageMinimalAvailablePercentage: ~ + # -- Percentage of disk space that is not allocated to the default disk on each new Longhorn node. + storageReservedPercentageForDefaultDisk: ~ + # -- Upgrade Checker that periodically checks for new Longhorn versions. When a new version is available, a notification appears on the Longhorn UI. This setting is enabled by default + upgradeChecker: ~ + # -- Default number of replicas for volumes created using the Longhorn UI. For Kubernetes configuration, modify the `numberOfReplicas` field in the StorageClass. The default value is "3". + defaultReplicaCount: ~ + # -- Default Longhorn StorageClass. "storageClassName" is assigned to PVs and PVCs that are created for an existing Longhorn volume. "storageClassName" can also be used as a label, so it is possible to use a Longhorn StorageClass to bind a workload to an existing PV without creating a Kubernetes StorageClass object. The default value is "longhorn-static". + defaultLonghornStaticStorageClass: ~ + # -- Number of seconds that Longhorn waits before checking the backupstore for new backups. The default value is "300". When the value is "0", polling is disabled. + backupstorePollInterval: ~ + # -- Number of minutes that Longhorn keeps a failed backup resource. When the value is "0", automatic deletion is disabled. + failedBackupTTL: ~ + # -- Setting that restores recurring jobs from a backup volume on a backup target and creates recurring jobs if none exist during backup restoration. + restoreVolumeRecurringJobs: ~ + # -- Maximum number of successful recurring backup and snapshot jobs to be retained. When the value is "0", a history of successful recurring jobs is not retained. + recurringSuccessfulJobsHistoryLimit: ~ + # -- Maximum number of failed recurring backup and snapshot jobs to be retained. When the value is "0", a history of failed recurring jobs is not retained. + recurringFailedJobsHistoryLimit: ~ + # -- Maximum number of snapshots or backups to be retained. + recurringJobMaxRetention: ~ + # -- Maximum number of failed support bundles that can exist in the cluster. When the value is "0", Longhorn automatically purges all failed support bundles. + supportBundleFailedHistoryLimit: ~ + # -- Taint or toleration for system-managed Longhorn components. + # Specify values using a semicolon-separated list in `kubectl taint` syntax (Example: key1=value1:effect; key2=value2:effect). + taintToleration: ~ + # -- Node selector for system-managed Longhorn components. + systemManagedComponentsNodeSelector: ~ + # -- PriorityClass for system-managed Longhorn components. + # This setting can help prevent Longhorn components from being evicted under Node Pressure. + # Notice that this will be applied to Longhorn user-deployed components by default if there are no priority class values set yet, such as `longhornManager.priorityClass`. + priorityClass: &defaultPriorityClassNameRef "longhorn-critical" + # -- Setting that allows Longhorn to automatically salvage volumes when all replicas become faulty (for example, when the network connection is interrupted). Longhorn determines which replicas are usable and then uses these replicas for the volume. This setting is enabled by default. + autoSalvage: ~ + # -- Setting that allows Longhorn to automatically delete a workload pod that is managed by a controller (for example, daemonset) whenever a Longhorn volume is detached unexpectedly (for example, during Kubernetes upgrades). After deletion, the controller restarts the pod and then Kubernetes handles volume reattachment and remounting. + autoDeletePodWhenVolumeDetachedUnexpectedly: ~ + # -- Setting that prevents Longhorn Manager from scheduling replicas on a cordoned Kubernetes node. This setting is enabled by default. + disableSchedulingOnCordonedNode: ~ + # -- Setting that allows Longhorn to schedule new replicas of a volume to nodes in the same zone as existing healthy replicas. Nodes that do not belong to any zone are treated as existing in the zone that contains healthy replicas. When identifying zones, Longhorn relies on the label "topology.kubernetes.io/zone=" in the Kubernetes node object. + replicaZoneSoftAntiAffinity: ~ + # -- Setting that allows scheduling on disks with existing healthy replicas of the same volume. This setting is enabled by default. + replicaDiskSoftAntiAffinity: ~ + # -- Policy that defines the action Longhorn takes when a volume is stuck with a StatefulSet or Deployment pod on a node that failed. + nodeDownPodDeletionPolicy: ~ + # -- Policy that defines the action Longhorn takes when a node with the last healthy replica of a volume is drained. + nodeDrainPolicy: ~ + # -- Setting that allows automatic detaching of manually-attached volumes when a node is cordoned. + detachManuallyAttachedVolumesWhenCordoned: ~ + # -- Number of seconds that Longhorn waits before reusing existing data on a failed replica instead of creating a new replica of a degraded volume. + replicaReplenishmentWaitInterval: ~ + # -- Maximum number of replicas that can be concurrently rebuilt on each node. + concurrentReplicaRebuildPerNodeLimit: ~ + # -- Maximum number of volumes that can be concurrently restored on each node using a backup. When the value is "0", restoration of volumes using a backup is disabled. + concurrentVolumeBackupRestorePerNodeLimit: ~ + # -- Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the "volume-head-xxx.img" file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. This setting applies only to volumes created using the Longhorn UI. + disableRevisionCounter: "true" + # -- Image pull policy for system-managed pods, such as Instance Manager, engine images, and CSI Driver. Changes to the image pull policy are applied only after the system-managed pods restart. + systemManagedPodsImagePullPolicy: ~ + # -- Setting that allows you to create and attach a volume without having all replicas scheduled at the time of creation. + allowVolumeCreationWithDegradedAvailability: ~ + # -- Setting that allows Longhorn to automatically clean up the system-generated snapshot after replica rebuilding is completed. + autoCleanupSystemGeneratedSnapshot: ~ + # -- Setting that allows Longhorn to automatically clean up the snapshot generated by a recurring backup job. + autoCleanupRecurringJobBackupSnapshot: ~ + # -- Maximum number of engines that are allowed to concurrently upgrade on each node after Longhorn Manager is upgraded. When the value is "0", Longhorn does not automatically upgrade volume engines to the new default engine image version. + concurrentAutomaticEngineUpgradePerNodeLimit: ~ + # -- Number of minutes that Longhorn waits before cleaning up the backing image file when no replicas in the disk are using it. + backingImageCleanupWaitInterval: ~ + # -- Number of seconds that Longhorn waits before downloading a backing image file again when the status of all image disk files changes to "failed" or "unknown". + backingImageRecoveryWaitInterval: ~ + # -- Percentage of the total allocatable CPU resources on each node to be reserved for each instance manager pod when the V1 Data Engine is enabled. The default value is "12". + guaranteedInstanceManagerCPU: ~ + # -- Setting that notifies Longhorn that the cluster is using the Kubernetes Cluster Autoscaler. + kubernetesClusterAutoscalerEnabled: ~ + # -- Setting that allows Longhorn to automatically delete an orphaned resource and the corresponding data (for example, stale replicas). Orphaned resources on failed or unknown nodes are not automatically cleaned up. + orphanAutoDeletion: ~ + # -- Storage network for in-cluster traffic. When unspecified, Longhorn uses the Kubernetes cluster network. + storageNetwork: ~ + # -- Flag that prevents accidental uninstallation of Longhorn. + deletingConfirmationFlag: ~ + # -- Timeout between the Longhorn Engine and replicas. Specify a value between "8" and "30" seconds. The default value is "8". + engineReplicaTimeout: ~ + # -- Setting that allows you to enable and disable snapshot hashing and data integrity checks. + snapshotDataIntegrity: ~ + # -- Setting that allows disabling of snapshot hashing after snapshot creation to minimize impact on system performance. + snapshotDataIntegrityImmediateCheckAfterSnapshotCreation: ~ + # -- Setting that defines when Longhorn checks the integrity of data in snapshot disk files. You must use the Unix cron expression format. + snapshotDataIntegrityCronjob: ~ + # -- Setting that allows Longhorn to automatically mark the latest snapshot and its parent files as removed during a filesystem trim. Longhorn does not remove snapshots containing multiple child files. + removeSnapshotsDuringFilesystemTrim: ~ + # -- Setting that allows fast rebuilding of replicas using the checksum of snapshot disk files. Before enabling this setting, you must set the snapshot-data-integrity value to "enable" or "fast-check". + fastReplicaRebuildEnabled: ~ + # -- Number of seconds that an HTTP client waits for a response from a File Sync server before considering the connection to have failed. + replicaFileSyncHttpClientTimeout: ~ + # -- Number of seconds that Longhorn allows for the completion of replica rebuilding and snapshot cloning operations. + longGRPCTimeOut: ~ + # -- Log levels that indicate the type and severity of logs in Longhorn Manager. The default value is "Info". (Options: "Panic", "Fatal", "Error", "Warn", "Info", "Debug", "Trace") + logLevel: ~ + # -- Setting that allows you to specify a backup compression method. + backupCompressionMethod: ~ + # -- Maximum number of worker threads that can concurrently run for each backup. + backupConcurrentLimit: ~ + # -- Maximum number of worker threads that can concurrently run for each restore operation. + restoreConcurrentLimit: ~ + # -- Setting that allows you to enable the V1 Data Engine. + v1DataEngine: ~ + # -- Setting that allows you to enable the V2 Data Engine, which is based on the Storage Performance Development Kit (SPDK). The V2 Data Engine is a preview feature and should not be used in production environments. + v2DataEngine: ~ + # -- Setting that allows you to configure maximum huge page size (in MiB) for the V2 Data Engine. + v2DataEngineHugepageLimit: ~ + # -- Number of millicpus on each node to be reserved for each Instance Manager pod when the V2 Data Engine is enabled. The default value is "1250". + v2DataEngineGuaranteedInstanceManagerCPU: ~ + # -- Setting that allows scheduling of empty node selector volumes to any node. + allowEmptyNodeSelectorVolume: ~ + # -- Setting that allows scheduling of empty disk selector volumes to any disk. + allowEmptyDiskSelectorVolume: ~ + # -- Setting that allows Longhorn to periodically collect anonymous usage data for product improvement purposes. Longhorn sends collected data to the [Upgrade Responder](https://github.com/longhorn/upgrade-responder) server, which is the data source of the Longhorn Public Metrics Dashboard (https://metrics.longhorn.io). The Upgrade Responder server does not store data that can be used to identify clients, including IP addresses. + allowCollectingLonghornUsageMetrics: ~ + # -- Setting that temporarily prevents all attempts to purge volume snapshots. + disableSnapshotPurge: ~ + # -- Maximum snapshot count for a volume. The value should be between 2 to 250 + snapshotMaxCount: ~ + # -- Setting that allows you to configure the log level of the SPDK target daemon (spdk_tgt) of the V2 Data Engine. + v2DataEngineLogLevel: ~ + # -- Setting that allows you to configure the log flags of the SPDK target daemon (spdk_tgt) of the V2 Data Engine. + v2DataEngineLogFlags: ~ + # -- Setting that freezes the filesystem on the root partition before a snapshot is created. + freezeFilesystemForSnapshot: ~ + # -- Setting that automatically cleans up the snapshot when the backup is deleted. + autoCleanupSnapshotWhenDeleteBackup: ~ + # -- Turn on logic to detect and move RWX volumes quickly on node failure. + rwxVolumeFastFailover: ~ + +privateRegistry: + # -- Setting that allows you to create a private registry secret. + createSecret: ~ + # -- URL of a private registry. When unspecified, Longhorn uses the default system registry. + registryUrl: ~ + # -- User account used for authenticating with a private registry. + registryUser: ~ + # -- Password for authenticating with a private registry. + registryPasswd: ~ + # -- Kubernetes secret that allows you to pull images from a private registry. This setting applies only when creation of private registry secrets is enabled. You must include the private registry name in the secret name. + registrySecret: ~ + +longhornManager: + log: + # -- Format of Longhorn Manager logs. (Options: "plain", "json") + format: plain + # -- PriorityClass for Longhorn Manager. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn Manager on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn Manager DaemonSet, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn Manager. Specify the nodes allowed to run Longhorn Manager. + nodeSelector: {} + ## If you want to set node selector for Longhorn Manager DaemonSet, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + # -- Annotation for the Longhorn Manager service. + serviceAnnotations: {} + ## If you want to set annotations for the Longhorn Manager service, delete the `{}` in the line above + ## and uncomment this example block + # annotation-key1: "annotation-value1" + # annotation-key2: "annotation-value2" + +longhornDriver: + # -- PriorityClass for Longhorn Driver. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn Driver on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn Driver Deployer Deployment, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn Driver. Specify the nodes allowed to run Longhorn Driver. + nodeSelector: {} + ## If you want to set node selector for Longhorn Driver Deployer Deployment, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + +longhornUI: + # -- Replica count for Longhorn UI. + replicas: 2 + # -- PriorityClass for Longhorn UI. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn UI on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn UI Deployment, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn UI. Specify the nodes allowed to run Longhorn UI. + nodeSelector: {} + ## If you want to set node selector for Longhorn UI Deployment, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + +ingress: + # -- Setting that allows Longhorn to generate ingress records for the Longhorn UI service. + enabled: false + + # -- IngressClass resource that contains ingress configuration, including the name of the Ingress controller. + # ingressClassName can replace the kubernetes.io/ingress.class annotation used in earlier Kubernetes releases. + ingressClassName: ~ + + # -- Hostname of the Layer 7 load balancer. + host: sslip.io + + # -- Setting that allows you to enable TLS on ingress records. + tls: false + + # -- Setting that allows you to enable secure connections to the Longhorn UI service via port 443. + secureBackends: false + + # -- TLS secret that contains the private key and certificate to be used for TLS. This setting applies only when TLS is enabled on ingress records. + tlsSecret: longhorn.local-tls + + # -- Default ingress path. You can access the Longhorn UI by following the full ingress path {{host}}+{{path}}. + path: / + + # -- Ingress path type. To maintain backward compatibility, the default value is "ImplementationSpecific". + pathType: ImplementationSpecific + + ## If you're using kube-lego, you will want to add: + ## kubernetes.io/tls-acme: true + ## + ## For a full list of possible ingress annotations, please see + ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/annotations.md + ## + ## If tls is set to true, annotation ingress.kubernetes.io/secure-backends: "true" will automatically be set + # -- Ingress annotations in the form of key-value pairs. + annotations: + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: true + + # -- Secret that contains a TLS private key and certificate. Use secrets if you want to use your own certificates to secure ingresses. + secrets: + ## If you're providing your own certificates, please use this to add the certificates as secrets + ## key and certificate should start with -----BEGIN CERTIFICATE----- or + ## -----BEGIN RSA PRIVATE KEY----- + ## + ## name should line up with a tlsSecret set further up + ## If you're using kube-lego, this is unneeded, as it will create the secret for you if it is not set + ## + ## It is also possible to create and manage the certificates outside of this helm chart + ## Please see README.md for more information + # - name: longhorn.local-tls + # key: + # certificate: + +# -- Setting that allows you to enable pod security policies (PSPs) that allow privileged Longhorn pods to start. This setting applies only to clusters running Kubernetes 1.25 and earlier, and with the built-in Pod Security admission controller enabled. +enablePSP: false + +# -- Specify override namespace, specifically this is useful for using longhorn as sub-chart and its release namespace is not the `longhorn-system`. +namespaceOverride: "" + +# -- Annotation for the Longhorn Manager DaemonSet pods. This setting is optional. +annotations: {} + +serviceAccount: + # -- Annotations to add to the service account + annotations: {} + +metrics: + serviceMonitor: + # -- Setting that allows the creation of a Prometheus ServiceMonitor resource for Longhorn Manager components. + enabled: false + # -- Additional labels for the Prometheus ServiceMonitor resource. + additionalLabels: {} + # -- Annotations for the Prometheus ServiceMonitor resource. + annotations: {} + # -- Interval at which Prometheus scrapes the metrics from the target. + interval: "" + # -- Timeout after which Prometheus considers the scrape to be failed. + scrapeTimeout: "" + # -- Configures the relabeling rules to apply the target’s metadata labels. See the [Prometheus Operator + # documentation](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.Endpoint) for + # formatting details. + relabelings: [] + # -- Configures the relabeling rules to apply to the samples before ingestion. See the [Prometheus Operator + # documentation](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.Endpoint) for + # formatting details. + metricRelabelings: [] + +## openshift settings +openshift: + # -- Setting that allows Longhorn to integrate with OpenShift. + enabled: false + ui: + # -- Route for connections between Longhorn and the OpenShift web console. + route: "longhorn-ui" + # -- Port for accessing the OpenShift web console. + port: 443 + # -- Port for proxy that provides access to the OpenShift web console. + proxy: 8443 + +# -- Setting that allows Longhorn to generate code coverage profiles. +enableGoCoverDir: false diff --git a/index.yaml b/index.yaml index 9d138765cc..b4e637e395 100755 --- a/index.yaml +++ b/index.yaml @@ -4597,6 +4597,49 @@ entries: urls: - assets/longhorn/longhorn-105.1.1+up1.7.3.tgz version: 105.1.1+up1.7.3 + - annotations: + catalog.cattle.io/auto-install: longhorn-crd=match + catalog.cattle.io/certified: rancher + catalog.cattle.io/display-name: Longhorn + catalog.cattle.io/kube-version: '>= 1.23.0-0' + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/permits-os: linux,windows + catalog.cattle.io/provides-gvr: longhorn.io/v1beta1 + catalog.cattle.io/rancher-version: '>= 2.10.0-0 < 2.11.0-0' + catalog.cattle.io/release-name: longhorn + catalog.cattle.io/type: cluster-tool + catalog.cattle.io/upstream-version: 1.7.2 + apiVersion: v1 + appVersion: v1.7.2 + created: "2025-03-02T13:05:26.229981532-03:00" + description: Longhorn is a distributed block storage system for Kubernetes. + digest: b113e32fb2c259e7772729a287cb62b85d24cdd2e1e137cd3f3dfd55aa17bb9e + home: https://github.com/longhorn/longhorn + icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/longhorn/icon/color/longhorn-icon-color.png + keywords: + - longhorn + - storage + - distributed + - block + - device + - iscsi + - nfs + maintainers: + - email: maintainers@longhorn.io + name: Longhorn maintainers + name: longhorn + sources: + - https://github.com/longhorn/longhorn + - https://github.com/longhorn/longhorn-engine + - https://github.com/longhorn/longhorn-instance-manager + - https://github.com/longhorn/longhorn-share-manager + - https://github.com/longhorn/longhorn-manager + - https://github.com/longhorn/longhorn-ui + - https://github.com/longhorn/longhorn-tests + - https://github.com/longhorn/backing-image-manager + urls: + - assets/longhorn/longhorn-105.1.0+up1.7.2.tgz + version: 105.1.0+up1.7.2 - annotations: catalog.cattle.io/auto-install: longhorn-crd=match catalog.cattle.io/certified: rancher diff --git a/release.yaml b/release.yaml index 6cc0cbec20..340c7480c6 100644 --- a/release.yaml +++ b/release.yaml @@ -1,2 +1,3 @@ longhorn: - 105.1.1+up1.7.3 + - 105.1.0+up1.7.2 From 587b6f4a9717e99b08098d767e7d22e9342441df Mon Sep 17 00:00:00 2001 From: nicholasSUSE Date: Sun, 2 Mar 2025 13:05:36 -0300 Subject: [PATCH 4/9] fp: longhorn-105.0.1+up1.6.4 --- assets/longhorn/longhorn-105.0.1+up1.6.4.tgz | Bin 0 -> 30914 bytes charts/longhorn/105.0.1+up1.6.4/.helmignore | 21 + charts/longhorn/105.0.1+up1.6.4/Chart.yaml | 39 + charts/longhorn/105.0.1+up1.6.4/README.md | 50 + charts/longhorn/105.0.1+up1.6.4/app-readme.md | 27 + .../longhorn/105.0.1+up1.6.4/questions.yaml | 908 ++++++++++++++++++ .../105.0.1+up1.6.4/templates/NOTES.txt | 5 + .../105.0.1+up1.6.4/templates/_helpers.tpl | 66 ++ .../templates/clusterrole.yaml | 77 ++ .../templates/clusterrolebinding.yaml | 49 + .../templates/daemonset-sa.yaml | 167 ++++ .../templates/default-setting.yaml | 229 +++++ .../templates/deployment-driver.yaml | 135 +++ .../templates/deployment-ui.yaml | 186 ++++ .../105.0.1+up1.6.4/templates/ingress.yaml | 37 + ...king-image-data-source-network-policy.yaml | 27 + .../backing-image-manager-network-policy.yaml | 27 + .../instance-manager-networking.yaml | 27 + .../manager-network-policy.yaml | 35 + .../recovery-backend-network-policy.yaml | 17 + .../ui-frontend-network-policy.yaml | 46 + .../webhook-network-policy.yaml | 33 + .../templates/postupgrade-job.yaml | 56 ++ .../templates/preupgrade-job.yaml | 55 ++ .../templates/priorityclass.yaml | 9 + .../105.0.1+up1.6.4/templates/psp.yaml | 66 ++ .../templates/registry-secret.yaml | 13 + .../templates/serviceaccount.yaml | 40 + .../templates/servicemonitor.yaml | 40 + .../105.0.1+up1.6.4/templates/services.yaml | 47 + .../templates/storageclass.yaml | 50 + .../templates/tls-secrets.yaml | 16 + .../templates/uninstall-job.yaml | 57 ++ .../105.0.1+up1.6.4/templates/userroles.yaml | 53 + .../templates/validate-install-crd.yaml | 35 + .../templates/validate-psp-install.yaml | 7 + charts/longhorn/105.0.1+up1.6.4/values.yaml | 507 ++++++++++ index.yaml | 43 + release.yaml | 1 + 39 files changed, 3303 insertions(+) create mode 100644 assets/longhorn/longhorn-105.0.1+up1.6.4.tgz create mode 100644 charts/longhorn/105.0.1+up1.6.4/.helmignore create mode 100644 charts/longhorn/105.0.1+up1.6.4/Chart.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/README.md create mode 100644 charts/longhorn/105.0.1+up1.6.4/app-readme.md create mode 100644 charts/longhorn/105.0.1+up1.6.4/questions.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/NOTES.txt create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/_helpers.tpl create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/clusterrole.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/clusterrolebinding.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/daemonset-sa.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/default-setting.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/deployment-driver.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/deployment-ui.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/ingress.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/network-policies/backing-image-data-source-network-policy.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/network-policies/backing-image-manager-network-policy.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/network-policies/instance-manager-networking.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/network-policies/manager-network-policy.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/network-policies/recovery-backend-network-policy.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/network-policies/ui-frontend-network-policy.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/network-policies/webhook-network-policy.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/postupgrade-job.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/preupgrade-job.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/priorityclass.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/psp.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/registry-secret.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/serviceaccount.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/servicemonitor.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/services.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/storageclass.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/tls-secrets.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/uninstall-job.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/userroles.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/validate-install-crd.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/templates/validate-psp-install.yaml create mode 100644 charts/longhorn/105.0.1+up1.6.4/values.yaml diff --git a/assets/longhorn/longhorn-105.0.1+up1.6.4.tgz b/assets/longhorn/longhorn-105.0.1+up1.6.4.tgz new file mode 100644 index 0000000000000000000000000000000000000000..39fad324930a22d9cdcbfe94682543dbdd3fde6a GIT binary patch literal 30914 zcmV)gK%~DPiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMYccN;gdI5__TPFuf4*lGNlrBJgGY~K=O%M( zup1;1H5)wuniAvj@9fvuueYCM4+@V)zsM#<$;piR4_oX83WY+UP*o@tVwQ|2j3?X2 z6U=3Aj;HaTHvR1E?CiWaIDr3mc6Q4D?;RfO{%QB%<-zXm;m+ai!Jl?^_jmU8|Acln zj!Dgv35oficJAC(xpRMz2PX-WSW=dVeg~ltOB}OtFT_&Dq(|8{&Lj(HA|#IEKCtVh*tJEkvmps)gbT`&KKlB< zU!mRJ-hOW<*!jA)yaFjw91;&_F&C0dYm29ZPpK3E6MYoZB)i?Zp-IGUM15(_W;7xq z7|(bPUwxVF4vECOwY3Z-ioMwD?e3^vp#P=*+->d7y{tgd{wW zjK#IZvQ$V;@H9tgxA&rV(7`GF(Y~4Oc5s?{KcPfKM966>;hh~eLy%p{4> zFlOO35|VK|CP-5sjTlEiWJAIeB8ljACQS8bB4sN2+uLI*C)uzUvgx*yOs=mqRPEWK z9N+YG@k|gNvP6;KDx zz5V_2`oH&b=W+dii0279AtRi{5@`ki`RpW7=Lx!;P@zTp-;UnC2}X=hu~gE1L}Q`~ zoRBcaoS+%z6c1w}kYs2`P>O{h5u%A?XwEW@B$=i$2BANW*$~G{;dp|A09~?}a8N>^ z`GiG8ARNc+hC~V)&l04Bd=QZ|W^)pukWEvTkVFb3vT%a1$VKH_JtepDH&G`m7gp852cAgQ^`! zv(R!fR;$yz2PO1NQ{>!y>Z5KKz8YocSgQ;grh$4vq@>9h$qAOa*Is8#?^%K{I@jtA z`bopG`bW;sEp|QguC$??MA4>BoK-WZdH`jic z=$daxvwk0SLG#OBlhKHTvX8p&*hM%YQ5KW@BTH2qYBaj1|HyFM^}AH%n!ER^zyc19 z>s*zBPL+ER=@B=hnAfYLyyg+Jq%Fh+A*GARynY|~lzjy#^mDQmo2^o3m6ml`J&mGc zSKwV?hE&J`7CgKNe`rY1^FRWph#k(|W{hanLl`5f*k ziva5i`W{0E)$C9M*z%@4tM39 z;kP}doHI_Mz_vzNP*yU1d6SZmj^=qg#A^phJhqb@kDWcDej7!sHTp&l-w}VS{w?aj z)Ng4)4>H;s`Kz-#;+@fjC}(sjwpQVPyCU7sOuY>aK*jD@)Gb@M^^kydvT6@6RHY4d zuV@}E>Kl}7-7#atoT*|h`}eJ`f}l>Rd+4VLNl=yuz>1Q{Q*Sb1BwFMvnyXTz-s)OJ z5L3gDqVs_jpn+|)i3%G{f{ZS?-2#Q+dtR|yA+dUeiw>(wV$St0xG1)@he`I(L_N{Gw zn{hg(NdWDumEd;Xeb&=HJYh^+oTjm|Us)2*mBIQxCCP=V46X=KHxk`$6Nwj~|NeNe z{r-m&WIW^Optp+{M=@3m{FEkPoJ9&B@B85vx|z^$0{+GsrZHIFSfVx^?JEFlb{2*e zdI>$$DsGy^u{FcBU%&v9Oqt}%JvUozynlL;DR}^|&J<<}0q|7J`{-=+j>!Qhf+Vuj z5rofZ2ouy=jmC`u@4?*HZYK|-?NSmt@g@WH*k~n)uf-)0mE6h$3vzlr5-7zSPl+U4tP1k&^+*g< zZQ;+?bCSk1#3*E0B3A_ozYTqt*aK^m(UR#+XhEQpg4$fH#9@Av6XIIl)O3D~@0zgwc$}*_0qW0);^e zq(M=EOejHA!1bI+OcRCa35kg$fF#%LTOp*swD*~+#TQNK*!Y+MEk`wj--xp*VhI6; z2ho}^InlFHS5=@&-qQ;r(Yx0dXsQQ1&1q0ODDdU{r~liuDLM!xBa!#LtGk+UPLuIp z*|6wlZ`oPJ8V(5hl?{t7Zrsd>)<^8`jo9H|6&yNEM8=86^B)_B1calxAnC;NjlTLd1wb36r`h545I(02z@9 z%{m0RHMT-v-HLj90Wb9$)Ih7^O0*`${>CyGI6LeZ{q^GgJ0v7`!gz|)!le58(=XkO z$G>#@zjSS|Nzuh=wEUjf2L}X8dU%R|V+p@hU_AXZts!3(Lu+{S3C>yHVk1ba9 zBBz5np*M4HsGO8IQsS{*a*C1#MkVJ0weXlovaJyo(kR!$?P2En&2l>7OtLAKG;~f6 z#L1M+aEzi1a2R>I9H-O8i-@Ne&~c)SZzc83PNw?PX*OC*n6eqM{t0mc4d%MzC8yIq zGH^Pbl#{D;%yC43RkW_&D%2n)e8l(^rJMwr24VQNhfXv?MHvLEoQYjkzr8_JKacpB zq2m)}m4eEFzN7MeDv)3??8^ch{mO=?b_dtjjoTt?5w&KnM%bujLSinhNULm3o?tR% ziPCijEOLF+#eEw$7R+jn0)4E|x0iR}qsPdcglsw`NhHuUA!!Ay8Er)a(+3j<3SbQ} zI%X3ANOGMGm4b*kV-iJ_10T=V^tKpa=Zwh{%C$6UR`!oC&d`zB0a&9!^t8L*eWseV z+XzL2V0q)7JN-`Wd*1t1Q7{hGJ2h|owyQSn`6lnwyyprnqtGcvvgDx~r%9ADnn=A& zDFed9Vi*-8OO=!*1)=ut^@WmR$7lNgqo3fv?~cJ8a`Zn}=cgdpboEQj$HXVYJ3Mu^ za30Ex1PM8j2n)eNiq+!k)&>m-Nr2QVK|barB8j9pz5obbOUs0e6Z<%h=Z1GZ(=Umv z7HJ79l&~{Y(c-aSvS>|~X9-LN)!w;h7X37#G5HZ-pAeWP(b~8=?bdQaM8&mUS6NbC zT4OvUG3u(fJwMuB0|^X>K!JFr#8MYMr6Z-LYq7503$0f^GwfNAbW}LQyGHM696-5+@VW^TvWG4! zbB7Al-JW5-9n)bRq}=TlT?_*(CpGOwzJH^Kjw;sq1dC!JM3sIBzYsU#z)S^G#h40A zn+ihB6`&QiaZQmUTdvOQy1gd9$U-I)I>-!k?E>pe2#)1sZt--^Ccw$GSacVAoPdUN zi;EVF0ONv<m&dNu*NJ*~p!=aPfsh0yGLi7;zF~NoQbNPB4$O=NW}K#UYG-J#X#q>;N+v;O}RI zyS0uc;~axVw5Bwn(`@SX6ed#Mu$hshrlc)|$ZbeSq*+KZiQ}3=TY70xz=uk?Awn%f znmeFimPi_-DdS38$02lZs+6-FmYRH-AWhWRJM@Y1R^f}|BU`%#F#tQ=xSa*c=*@@8 z2$6c3LvHdJ3eqsg<(vq@XC%s-d(F5fc|44adWejEXxxf~Qx;k2td&#hDE=1wdWHU!F3&}g3C49s;Drs^_A8UpzPH zS|^L`QENKFPojZ_kNTwirv=kjKPnA|0pc9qiD2R`ixPlEzKIqSBaVe5?-|H8cl{zaOru ziPS)#ORQ{U#=X-qD;&Le;=(%2F)_W2VkF3vhAd`DAV`WitSzzW{KxBTNJ1Iw!y+G% zm?sk7dT#J*GT(g#0C)TPu+4v|cYFHXo_PnJfy#N4|J{5-t6i5`og>M$I8GU-a-Q!e zwk2FayHU(BA#sXQPG%&Lb=9=M8xnBB%_z9(vm_#1cXhyt5E&;L`a346)g{5Gy`gao zia!LaM1>O;IPRg zyU_hz+b;uaIPsM--(a`QKAa~?5M@A< zv8AyNgBY+#3G|{r?8@s%(-@ekUyTaW6W?=Zq+B%L*)GP$Zzs`rZ}idX&sKVyNc^`c0`|SmX+R*+J6-31`;Ph=DpVBuW%$(_n5u zaDt?wg5fG}D*z&hWOyHpJfs`y|F&oc&#q))#?yLXx zKM=*@`Gyq*{<~|@Dvg@8S8^ARs^8kbROkBAeok%=1bMS*CAc5-17BouaAFLSS0OrEX+>t4fI$6GvFfXQ}s1@Xd)!Rk%H@)^qv^e z1dIrX_{j4MoA2i&jY&cU$mgFhl{JQLRbO}9@4H4rmMGPqBvQL*GaAc+dmlXbuF$zf zKoyJzgezIK+zhefv!G=#IHTgug4M6J;nHY3c*d*WSh0559?zTCJfJP}bB#ws#|k{^ zHk)qVB6;k;(8gEdZa6JVk=u^Ub$G3V(aj!(&YC!3(-T8qDQ7@b?gazzrjL#04a%{ z!TJaGf$6lQx6?aa5C0m@Gi8g&?H2|8S?|WsDm9~*{Nb;wX}*&Heiu}{tUc0_=Q5# z#KhRW#U!e1iCTZ+1kWt{IoV*f8dXd0Gf=&jYe~iOO;J5la`mDG!f-6YBs&DXRNl6Z`1k{jznVwq`sB#v!( zslpdx;82*$udY^4x=Oq3X32HJZjx@fC+9|pH*}@Azvt~w>McDm_Kycw&XF!kAq2)F zsdw){T*Jpot^%dtHW4r5)P-cH*VwZLBGZs<~WgrL}$hP4abA4CLy5r@rW-5 zCPqRU*Jg1q-!pW~aT=spScEv%Q4zWEWWML0U8vn1-4_XBJe}YKR8JG@Ygc%Pf)^=E zBB!brT@FIxICsW8>!J5$STKf0wPhR`&atVXz;RZV2r$>w+MX&BXzY%xGok3wG+R*4 z>7>^q3}A!Wp4!zL$H@|jIzW8RXWAfHmuDJ z)uUv5%#so1Qz)b0`OauMC2ASAC!p#Q%V^(=wbw6PY_;ZTTeJI37fN>bce+-VG|ho; zx;h_^0&lc=gGf8Q!p7PrkyXUNAA*x<@o0__3_WP2yBNz1P z?P=uA=`d3J+G;8aTL`95nk}8CI0Vba#Q&PmR5kk>u{xVhNkp;K8}8s|vn#UIdm60+ zV@`vx%Kh6qqyRKVM;bP=#LD}SOX?m()=x7b^_hqXL01XAMIl!b^fu*02(yhb#j>$0 z$DAdbqr(>CsUVW&sR*zq(+-&D>8x_>sHc9_1^>om-davbp%%pMp-L1aNs z4Aj^MIXCE;s+MIv)AX{ea0~#2uHH-*B~!e*W;AFQI6>cEUJg(gQ#D>%$Ix-`dO;Ax zZZ<0_qKkPFB3PHX)0kKyXhgUpO}-xhVO2BY`JoIc6)XkndnwanXu2wO-mo!>$&ADX zRhmRJR7MQw6ZY7UATwg;P0Yrij8#ve)(gM0WW>6KAlLy;XxQCC-Pc&+Sp9LzIfGNb zKVc3>0ihBc2^?l)^~WX0p*|WIv+)~+a68eNAB{04fHF|*{GAdxVO|i!asKTsd|GG& zsFe$>OHOd)`B{oimMqCtE8|n~+Os8>yK`1=&G>h62ZtAB(A;vnqcKG_PywFpsu%kA z>frW#aNc43Ar{&}hA)+0N~#ssC1pIWVzPicbQ z(r=%+9k?R$Aj=1s+-2&Bol!3KDO zt!Q&p#&N05aj0WQeUg2*h6Pfy+c839n#y_UaF}zp>fIvi#D)5&s=U9uue~^Hw5ek_ z8`@MKi*3S&$trD@juClbnJfm!BTiT{pR!DG3K+L)Skx$*$)Z#~&Spe!m1I0+g7|0H z1f2RY(CiUPo$T-#WW$(-=q-_) zh60^nF&Q$Q8?3zmYB#bnS}mR4Xlhbss$^yge>rHvx@WAhuARo8)YOa1^Pv zNNZd$K*ySHG#T3tT&Yno*f))>B-4~}%xUa-#c>=XEY&9o3eAbO+MC~xQqxMwudxtxo68#q6=BIB`PG?vWmpOO^H!L!BT}EPa zQYJqjQ91W=b^boT)NR_t5j^>jsS7*>_|3h8a+{10Gy$w=Z;n< zDm7tq+(rcG4yadtpL15|lp>0B!rHNSeE2okeZKp_EnG@FE-1TcY_ePYDp+EU+G@M8 zkKkK#pjTbKm{Kg$^98X?4N1-`D7&*OrPSgLfn_!M%Hd?a;({BTNWD)b{c`o~x>KfG z)_VqF?mz$iqa7+xRPd0^h;BtGYgwXCkD916<2y4~U_g&e#_ek|*P&bWDYKt=>9^s3 z`?4YVc0nXf39zH>@>j*6XQSJ(J#+uAe^NjjlQrCAcQ@-9GB-A3B7xTl&6N z{J!VNcjWH;X--Y<8(v{=fPgR~9@Q+jS7-i0Ub>0G#SCdEdiuEC(qaIuZK-rFGPjgr9KG1rv%G?d z#@6Q*sMi?eQGk0;NE+)Cv7~f!hrQ!MA3n&}Xy+azn8%b9&Tg9Yb};+O&4FQI`u#l< z(nt9XR+921f~a?MU>mTWFd_R$h?u55$~x_Rs+Vsrl(;Aj6G(+vl!swCI6=aU`+E*9 zprmHN(Trl9X7b=*U#oGd_P02^CP`FjU7_mRly2mGL++Z)^(i}jy`$csCi6f*u#P|yh3$?nd%kudFmOXXwE0}N;^>wWxd&^h^I8=>HjB0OH%-gqfD@evPx!oSdY-le_ zj94hPJ@CD0i+J}KXoR1htF1XQRiR~n;yy4Fk<47|Nyy7bVMAh`#n zxO`=T=$q2mP2yJ)dToQrZ?HC}|1_L_nIUzGP{owB;2gK;U3Dr9i|QRszg=t{O~P<* zjQ}vdM2O+kUadeq-=2PV_6{ANo?o85K07|TJcYN2aSh2UbAEAz2Ipr#9$lWIA5Q-U zUp#gL5p5cQwK+?z^UTQz;KWhJA>B)sE}fv#Txypk2_X@Qwp354)U0UymY$PJ2{tuQ zbY#xBgIifMsGSr#4@@jr;Q+iBimKzdsx)Sq6f`oc5EW=b;wcIzm}~H8;AS>DKRr5m zd)k|7Q44u2Xrir1%8UhxinoJ$GE?hpO5-zsdT8`JotBGG$|B8+RL=9uu$~Ss2I84l z4JHANN#STDg!?L9hIrq_G0`SkNhoD7DV+e@?d=@`P0i}BW0do3OBs!2Koc}zk(#F( zR~${LFoEjsgqTZmrvDgR4BWz~>0#7VHY1#?QF8YR+bo|(VmXcyWR%4wjfg@!cBgv< z64@|-k#(UXMpwzfTJ8d^v~+Xv$6m*kdv6fZ>7iS@b@G&Qa6MV&3WLK>W!cjUt*m&r5XaJb98|yJ2OR=oD_^ zXk||805r8s!wTZAh^R4{OV=%&vrKBa;@f0)OEu5yU;>Zx%O`Hg5M~IA%@pPeQr|oF zo>6Zq!1V*LhX@9ZHCqni9JZ`3f-g#rQCFjw8Mi2jwPRAG`H<(I<(TLo*BSs^aLAfrSi9Kj| zd~t>%=YJJjHjwPhJ7-vqK(iTpXhJ2$G5t*`4xJyVpb{z5wy;boHODSgewt8NoF2tV z?Nc-VKTJrR5-xf&jW^Q9lKH>?a`#1P{vRGZ&i{vbK7HDLj%IY)*De$q6FE=GtEnPO zI3a!XeEaj~jw;nTy-lqqQ8&nektBk@HG;?GoWi3_ndbk8s;tt7L`uSEi|C@T zE7ImGXr}+FJ&|n9l+#3xQ1{Ow__OGu-nsTG=$abrO7yJ9*c?SX8+a(&UMRGm+UT#k zPWGNvuvNmkzrFouVV%PLzZ~xDbUmQ!BduL`T~uoF(=T0|$%*)-+ee>%>HgXNp{gVUq~+2z^iDsWpl_&$s;%%498`5SYu0Q#rf2<-l67j-|t;8hVY$peDnT!Xc|ZZCSPtz?hW7ONOs zYRa3F*goP%X=*WD%z5Cf`(Wnq2Ro`c!_tvsfpN@+IPQg5%9!+Y%@dm!)l3qwi}D4$U^knRP@kx;ib()?v)3p(yQ&~9osY5@Aoo3 z6@9UFlf)GI;0o2!qvED@g_f5nj8cJ9wS#!ksI9*K*XVynb-*S1-;0C& zgOdLDVt;?NFvdJn!Vu8>~{i$QwsOY!3F{RB)5_zIt95# zO`oOHhw^o)FcXqZ?Ms-q;CB}tgl2>fO|kCtZlMMAbGQ5V0yOk$&oZZg1^Pemd+cASPmu3f6{|QT+#>se4;fIdP znc~zhW;R{~^h1Ka>4uPd; z4zUa;)dqfLLrnvH&U-l=ou;UEv?D5b276$`EE*de)nJ%iM7!a+w2l1Sm|@hK=1lw{ z1R#__-aua)No^80G{QFDE$A(q4J*%WS^v^w%}`Lsj-jABu(?IY&FP`uG8E1HF~uvG zy3ql*{$@tt^5fY;}K1KU8^dGbTsQySoVl)<8otk87(|kS=Fhrt`?(- zQ|i={0(1boh0Kyxg>U0>TD3CGB%GhTA;Sq{*M)dwJ%Bi-(Sjn49S049U`b%fx67{% z60c(2s4G`dR?4uRVJs#?3TdbGs+t>G4XQV2%~Cw zU8~h_OfgvUZ`I1Lc!yd&(v}6g8Q3hDXEf5Pw#C0l-AoWeU$Y>6Y1`}}p2haRVaq$Z z0hZYRdoOm&_W#Qlhc6%P|A%QHX7s5_=uy=Qf+=A3bj|#LR^}8Utkt2ax;FEQT zUhdM0G{66qvc`UDk>lK_uNB1>GUbB?%tBX~V7 z{et>N&HC>gc7ebf*#KC){_pO;e0f;${~tcae>}+J3qPEuBA0XSs6auyttq)6Og&A# ziELae)fry=u)<6dDGBvS0&`4Q2M;St&P3cB4?q(lb_(=u)UoTedRFiGH@;V^sZsSP zkPv%p*DC*{n}bn0(3V$~>~DA)H#J@Iuvsdp$DCUu+yN{fA1Wb=bYh{>_J47ESdGP} zPp&Iap;rze>2Z=WLE%Ec&!79t%S$}=sY%QC0#qQR?xSDNT8+orYV3PHp?nc^r!g&+ zrc<0mdD)(!wRZs&Wz8Q`vpaG_Eiw#E&q z@w^AD{lxgIB41axmf{5!>pn>D-x2u2_fu=JCCo&@2(RqCHoHT2qlq(2u=~ z!d%MTGr1s*LIH1!@+`2~B29Re&g;BL$SHCQU-Y^)YXC=F{&Kjp;|X!SdR3)zwbpK> zR>%^I*3D#L-Mva(=fqxCb-z*-?g+90knSrdIHCy=V!+vu`0La}%Je%@Sh`$lg4yo2 zzL4y<;@7%PBgk#4F!=uRa&Y0k=pB%^5INuz-Wo?U4+h+fIM8iRn2_5MnQd3mj0Bt+(-k+R8?>5s^O2S^kBG@Om%b8zfM zJn@H*zo!wj1zDj*3AKgSI_I_0axS$3GK+!y6a6D&k}SuG@p9O+pERwhvAQzFsOcM; zMC`_1MpTV`@l&{!Wdu&5)u6U2?BlEhpRJ9*YVCg_;}Lk_ORbufWMeee__`A;cLVlM z+wqqDXwN!+Lb*m%Y74E#JcYz{55qkLtXF5BLUl*?Z`S3X)d{_jgH{Ju<)OuWsk|s= zK6$rn=OaraEXjrBSd#Hvk2z;?Oq1~ye6nmX#kW@p);C7Rq>sA0J3D{wR`#TvN7n3D zJg`4Dw@g;_$1YtblwSuFw%DgSWxRE}{5ivt*{hwMz@D?eXDA5_u^VFs)L5Zu(OA_Xe%dJXiMlnM^C)KgsI+r3uy8F z&;H@d{qp($mpd;W<3AqcsTDLj)683(F51~HvB^5}VNKy>5vpU7ar zvB20aZ4oawu*r@cO8PlfeT9xer3bpMwJiD&EAozv9N1x zn%ra;bquLFf_Xy4HS9f-=pBoQaDCII+#HIixDH}nFn|Evg?(Ds#wI&sexG28l?Cq5 zcX(ro18s{hK(_>ClL(sA6&GwIj}l3bMsV6|?hrNK1Hnczz=@;*HboX<+yM3-Fh9y9 z`&Q=~t{{yw$pVvzxDC1Y{7Bg~&g)b#V!R-v z+VpZ+!<+1DR@i`YU9#Iup?<#*>mrDIke=pF1Gr18B0=q3*GV;7NKqf!J&F1^EX1)d zMGN9SHecI{d<*R!khR&SE|lFDntLh1saQchx7VR;V42=ze_q~|=C(Gk>A}IJ0gGds zz_X;}!S^6#aUA5yIhU$;6{wp;TqpJXR_l?MZydtc7&rIzY_NS5d37L3vB#e)bNE$drlYVWIJ8*WXtgZre|JQ=rM+IHB6R#Y6L| zE##%Be^stvN4*_=m*5F(_A8?a>i$<3Jq_73#i6V;n)iQGQ%xVl)_(fv*kuIuFJWGL z`f1pKO$L_d8wLMKAo9DSnr5Ys#=>JK2ZyKi)$Qv+V(N7bS6ur$?3As(-;`Ml5#91dB2vQaWHxrVS{oFz3)m+-KmKbc* zEH{^wyWB_blVipsmT1>>Zj|eCL7pTjU`Y^~q9DK*o8*hzxd%7x|FDECbu$0P60)YJ zxeoq4bmN4I>!sa*&4~57Q3rpM-B6ry!fuiQi-5f;OY|9^Xa1IW5V4yCW>I7c1!?t| zP;1y5?*PZN9&PoZHL5w3&3e|9h zzxbRCGa5$&!j*(98t{4HAnzj-4^qOlKE2$GZ`0)cbWt;i_8OjRPu#M8nw8bKC9UIc zt==wa{T|lWbE0>~U=P6C^{~q-H{bQ9!jkQedYBvaBl&vtfJNf0czCnPq)S;O%sI9+ zi{mzeaamIvk7dwC!!x z6%g38c6%HXoMh<*ko!B6Zalg$`QM64ZK%tdJM03RoIDC_y11p9?Bdq$sc*g)Ur+AE z-77k$jbK@|i_MMRkK{bEx321|Sj=(0Wx~_l)oM>0+wIo1YX$VY}OSqWiw()B~CKf=%+E!y7MKcQ_mZr%DT}KL6qsR0#`hcoKBZ` zB$l?f*%%>F@(q+1KvkmRgJ`qvHG;kePmv?P{s6 zm4}5G`t>)8*Ipf7d+qVsyMMgC&&DLhk7RSaD*e!}HGz=js?rzfz*x4b8M6LGDc zR9o11PmWov;L~Jm!@92o9+S8F3WZXKLRUDCBF_Yz2hru1_iJ%`_pt?Ubh<&t$2I%z zRu@jy=T=+oKD_&qPv5n1`IN-fT|7W-+rAH5!~{2bKK)2m6obzaQjTkpI`Q!NODEz#)O=nRT-Eu6+vJCUUSB zZ1vIZ>dAkr=s#c*;A-Q=^t?2o^0<i~jy!C}N0&69%NB$@ssJhzUv2p8ArIum9e$2sTrB;c)%V2)%AvuqM^1-Pv4wgemH;s{_;aHOQg#a=`q$au(cDU<{*M*PzB9|bJL9}}(+PG8&%gEywTu7n8 z`THNwF3#S++c=RLaBZSf72~^+N{5~*`D;>3;w2=jtFVxCAW%-u&we~T|8Rc#-Py(E z`O&6{xTF_N#BA=%-H6JGpua8SJzHoY@y<^#&i-fPJXeEX6N!pg-i<8Q#+A!R;}={= zo{M)!gNyIqUtVsUL=Ct$k*SLD-AEPF8FAUd7Za;kbRoIkoc(zE?)2h9iL-A{H%zfc zl$&T)hj?46`Rl4(I_ffMRB7PWy7SY)o3rDi4-G0uW%;gcrjqM+6~sMR-VS$v6@+JApmt`<-x-4L6uKPCG z?hC!^)OPI;kT=_yzjsQTT?^x$vSypM9+PI@U()Ov60e;zy9U-5N||jidCZu7&l$7p z=)8Wy>^f)5Tp_6LcOjJ2}BG*Axjc{5fqXPYUn0r6eFx_7jJ}CZ@fPHS3#dc>3d1XpHa8h z>S=`aq+k1{RLQisD_$>vP|dB&s})&_iwYKZ_{lR2<%Kk6EYnL$7FP`9Da78|TsBUMUf3KMR2irm zMbE9Pzh+3p@)oMT;o3SSzcvW2SdbbNyWK@bS|y_5Z1j%F0VjfZH={1QrF3<M8H;V>pHqMLLM|(%ugSc=@HLqi3WtncQ)1Tc zR~M(p=ckuV9mV|Br*6J{^t&yVm+n?~%vqLp`?)Nqth?3aM6iql7;|w+cdI)ieAw-G zbpo(%J|NBhRo{VH>Tf~r)N3UT{9bv{q^#UwiaTm3fz&dvCZn6W0DjT!wy2MiF->lR z5Qh_=isgG};rlj}E#F(4!+<+<76E|*^-%g~hIzoVMVH_5%)9e;nE)!xEXx#X{<)V8 zu|;p*zx(d{_vi0Eyghn%^xf%s@s8Jg2XIjkQ+E;EtFsS-_vf`cBVC1cx89j^uM1-R zY-xQ9=*n}9=wlDOk3Qv`s!^#jWSinX?=37}WV1is_R7`S-L_UL_3vq0D6T%A2`qulp4N}0y%Z=sYS-C_GA2!fK!tmIF-KYvPH2)FfrDeY^X z64X7%NjM=q029kaa2HKko4CeQ?xU{c8R>Q^eJ?GwBhC`J);*)v*Rf^?^fr#+LC|iB z#$w||p%yBXDs-)8l6jS4h9h%L7e5=Ir;8ANkhAE_7>&L$k&a>(t=XsLB<$sw?rS{(jbsu68wRP5H8eBCnrh zaa^7~o7?}X+5e--m=hs3vGb>&#ruCddprC4rTxFdgT2T7zXy5Bem*nyo;KkxK_*WY zO~$?JZ$x1)>`d2ObXL#+f50<>RS}TmP}%NjAcfvH{8rnu&cLu=i;JHwYmHygy!h## zTnRMv)is%Kp|8N`Mg3P51aSF&Yy{UjToZ7bz~8!V$#(fvz4W@Fi{^i4DrpGiw?!Yz z!m5S7@+>As;DVR04vhL>@dj6dwc@ax6#N?QvQew5b-NW{sdvd}4(1Zp@v~_flPO6w zK`&Ag(vjy`)wxpvxG>nRj&3K!QS4}=cjbIrS zea}QqQ5lQe=C0r2`_iK6@p*u!X8kupUguk;L~IxHhC=oQ?ZOTUMdwW#!;St#A0HEV@{>EAQ>WY`eRn7GtBC zS}hw!{GK`8!AMd4dgKn9231rV(5WgW{t@fd;52ltoDOAkkc&jSXYl@*JT6Wfe^!_O z_85CR+5e|D^8ZCy{=eAYJA9P?5Al3q`JW4qFD?6XOdjR_qul?udD_VTN@6u{`nPcs zE|vcWrTG87gBLG$9_9Z-JP$7aYsAyTi~brU9;N=H)c-ep+Q|RaHU8qWO#UCfI4sHk z{TDBGALai;JP$7aYee8Z%Ks**`$v)XwUHWk0TBusq;WQ;$sI+wy`^tBZ|EpmattFt zpY#!o!p&(tuZ=D59LDJ_6;hzjOR-+on%{?C*)Wh;T(8y8GD?@zMgBgQvo`YI-4tf_ z##UVjmdO8|!~K^f`G0uu@=^bPkmt+E|1wwoz83;7z&=1JXOe|1?xV|N8xF67hyHT7 zv;RAt>Ge;W`JYj@wY`=OxGetX#m+(5{y%tm@Hqb;;;9K$Y?1*@F+xuv1HKnRSO%cu z2)oao-G>OjAZ0hSYVeeumTT*tG+EiR`oPkmAVa; zRwD8BzWC!%SVNT@lM%gkVZh!QrnGv1u5SGgis8fc#eRQ*R&Cb*8#0_Qc71RDpS`{E z{_p;amyiCR2YJ4n{vWbrrr`yK!Twb&fZa+eoK4URM^h^P70I>tdy$3zj!%vJPnnSR zM*m;g@b2e8mdO8u7yG;A`=54RJl_BGAdfGlhDr+LlIgE(Sdd4R0~6f|iKjg=*;dl1 z+eeCV0>e4g0{R+wVzh^DAHhqJg&`pkiMEDh#5f7yt-X4>Dg{ezJoIH#IFxioP6z>K zIGD$dVw#W(5;8dE@fT1Ihd8`uqtP3EapvyQ#7~R6hVGUc%Fh5*%_mgJbWqdy@8({k zb#r}G?lf9(qft=hUR2JCvFyH`hO1|qE}m&~(+(#}JW1Q}_sMHa!S)X{kDybpE2zEJW9i^^jLhlRQy2s`QU4{i90%M^Nd1kJ}uz`oH$7gfZSs7O181pD)V!pI$uf|31*;>*vCy?XT=o z4t!5r%`Rm(-`3?+(h$ep^;O`Ah>+7%-!IZV)%U!-G1XAYB7r7&rmuUM(D8%_=^Teh zGNob72;34gM_EE{QxZxNAu^---k0GVs{Y{OKy1$mM_CdP4q_HT9C^k`x1)u{i54M! zG{UhUos<(Y1thK7G|+F}up7cH!8#_F@vdd|o!`&g|5L;K7wP75zx}C2{O94z^8HT- zhcEXY=l?@IwU?<4E(Ya@4{cU&&vu7IVkZ??bYU)TTOPlViuCSQv9c3rOvWVYBgr#m zpx`)WHv{|rRD?J-R}+~6octrBoJ1#_rN=nMLmE>_ZTP~w)5{O%M?YCWB&rs<_}j&Y zqm#F1?>hRPI1{pA1%ZBfHaIT67@VEtD7ahfKr7%`O#0|ty*x_hkhJm*O|sjDuOsmt zXIa`*H%o0wvlz;WhJs!Ob;u7tqT{zXgYZC8UnnW}iFQehm6nj82vX~e*geByHPIc_< zW9NFXo7g~PL&bS8K7|y?N6xlSmKpymc4SFI#-dmq?(fPBs9FE5@5S7Wa_{j!J1_PQ z%JDzDyN~(b9^_f#+5=BHDQ1dX$rIRcAt0X9!;WgoU8U0nT zq+@&1D}O0Dw)L#4%7XmQhaCT!`ELZLk(>9w|F^ea$^ZP~<>UFUhj|uV*lAb11uDj! z7uh@LC91*=m6LLMb%S;_Z*pzMXY0#cm{xw-)ut^dReLGgza+8RUe46=VkT28VRBvE zOFr46d=tfsUG-gvoJ4S~H(YB;l8~t7Xo~r~kG}rYRYTwHci$gna&m4;p4*b$t!~aK z-F|nr3wOTRuYFe?E)VW*!M$?cC2>JUyPrRQT}RT*F{82>8JEE@OQQH8cefvs5x=x( z{X;y>>;IG`R5Jbm>;K+CMgQN~e~kZmkjF?@Hyfu!avHi>`PMLj72H8dr8i7MlW{L( zoG<~`zLzDEfwIt7!P%6^3CToI4x06mA7|5+Ml_Lx&v1;~ zogVtPwnJ;l-yXOKIZnwXof4MimooS-H_{9zz{)fkJC5>R^%t|)H+O7Yzdo;`Q2DS1 zB99CCLp;sv|K=`$TDJc0ye!B69=_OlJpcC~&mu$Oey$sAJokN1XTz)a`z^X6&Ohi} zx+ks{slu^uRJu3LuTkA4dl+&z9UH%&ljR#Db{$TIGvj4idlkMEsT(qy-Am51jS;#A zr9v{ZGM%BkEBvL!*W+`?r*8e1jN>ucSoq)4^FNjQKXzXn96rYXJjhckC68Tj$RZ!2 z$0iTxLA2OZxU`S{3Bt+UzBnf4n=_uf`#bjgh_mUpIK0l%KI(QG4y{z1d@U~B{mlSI=sO~pVCt%M zTb_Ndf${cwBnFCTo*!uH-YrF;P<kFpBC;j zMJRvQ+<2khx{aIr2F~C-mv(FBSoj|sXKDdL;_f^x*FV7$>wBv&%QuKOLW>G@mcbq5 zvu;J`dCmGZ;Pj@*rtRR`2y0ubeO8E)=+SAw|H_8eQCJzExY-%z+G z_3I`q6`|g+5XV%`mkI0>uWWq^ip7%Pop-pT(%r&wpJhU!07>M>U)GTioJ`q_TqHOZ z6DGw;rl|Ou#zbdcyyVmyzuHry|I1jI z(7z420GGx89lor@|LpBQ#{WIY({T5+7pU>cT~uCkGrD4u^}_t}g|ofo@YO1o!&gfk zHnnkmG8WFpkg@26+-%f@giAW2A(jOF6AfP+kR(L*e(oOJEuo5ClX>BD5Cp&H`?YK4 zf0jTF;W*w<`i~a*|H|ioUK}1i?*Bi?v+4XCItxdO^c>CkI9$$-njkvMn*U-6IsAU1 z2TjLOZu#FV8ArAI0SbZ<jTV?scf} zqEb*9AdHimH;u?>@?j})IGK_}dh^kHX{-O;B~MWE`?;FcYotbKE1*b3<(l$IRecms zkK*Z3JUxo1`w~wxN^aH^PpaypczP61kK*ayS3Hf0RHb7o;Qt#e!-<;cRr{~T{-5EP zMoO62ZNQL6cX9tUWJ#&0&3=xIz6^fYGdI!jS^(PGv`U2h@l zqHb4T@4N%&gP(v0>#GsVk_h!*p@@dk`yhz4AN_U6rWV}(wl>zSt8?qE3CH;5?gnJN z+F814y**QJ6K!9DuwJ*e4kuo{_9?91Ya*^IuU_xWEca`V^*a`=-0a@=dsuWEaLfvy!Wu?bsI_uT$;bVrSso=J3D)i=f580xextsQBLV6UOKO*jqU2kI7I{!6B5U09J8TL=0lV57Nnn%bVg8$<-~iBlc@6qC1ec3 z1U*eT8PQu3=}a^K@vMj5C-EGy1ZpajP)az8X+nCP-pR#>3#Ej0o}gnkow5Y|czl5( z%0;I)rg9tp)#!J6!{7Ke{A*uK#@p&2`%}!4?HrKy*`N`PiRe7vaAbJ%4^SRTCU1^7-?Aou=*T=mim$M}j`)VU%Du zeavID5liBEPXqr6^Mod21=_(;%XIR!w4wzrBp7oH@@K@^6k&bS3r8lQijr0s#q1`3 zWx&5Gvp={$LYvwc%R+smn{T`4FC(6JKhAxk7@ zaZLEO*_=T!8`BWkevPS|WJ5^d=j1}ZV-CPNdmeo2azVx~pj)amVmD$?Oh+V~hcPkf z+LUeEu5k;(g>dhCXnu9#y+ui@qt-NxiUhVf@{^u4VGVDE5eC*Zx?^o*k z-mc=SxA>YMxO3{`5R1vjE%Y(Wc&z>((IlECQvEsRBvt?8o9mAtP(BXhYZ`q-6D-h> zYuR_@ z#H?g~(~8=M|JmtWNX#Wnilp*+3;jG`5wg}A8kk#FazR{4$uG7;mV_jgV%y%$vYoOh zus_WCqwQzf9t4u=v&fNNXG#=08l3eyog*b`IT2Ybx6t$F#{SC|b?y0c^ptTJ05sx6 zOx*gZn4wAuI~LEjP$mf1&MtR#nPf^A9x*;eSn)uR#%fVD*U0LTb>=C|iI2|e{s^8u z$io!Tcrk$x< zx~qm6;@EIF+=n-~806$c5lLe=s;hzxm`xRvMnqy7 z3q^mv{Nl4OlUY!^CSW^BP^B1C*-p&bfYGUOdb`lz@o zlrahtRI*i2ie)%KL5jZq)P?hVT^mI8`D+vea-Nb`Q^Lmt#S^iBL>~*|6=7I0C2LrE zVIbV1>%hXQ?Uhyx7Be-Bx}Oyt_UXVT*N}SiXbY9!9LJbWw+e}|w$KR(05wU~7c9vr zi!X@WLMNb0z@J2h%8+@jIPM%Lp^}!y{fka-)0lC>(bd@&O7M)1mB5t@9i^#&VKD4O z6yN6-;zvb~r1&lfdGt|@+L_~EfFkj**MVTWft7>={T$QeIu{#@l*?!NET@TDLp3A) z5xq5=e;l=Nng&X5o05(DfR>&A-#sYj|J^^>fAs%8$dmhjimnNaVmhA48>0RNr!Ix< z5Ve94Ea0BqOmCA&PKTM&Qim}MuWd3sWaMhmtn8up%671NhgEi!JdeqYKt-1)NILNb z#=NpghV$HA;~}iCDN|TSB!Uzjk;5bRdH^m2hZ6%AIwR&uIN>bO8nAI$C|F8h+j837 zGR3-u z%lNQ`9v-Dj!y+m`zm&|~Z=C1P$}2-1Q~y6YoyE?-s^hPP)9+qgem{fT5}mLxgF8@V zL7iN*E^H5DHr$?KwUBK?e{v`Iv(BUS`e?mATCa<(*R*P0Sp^ZSE6G(q=)+3( z@SEPqJu#&KvT*kw3>i}kO9v?ddGkSJLyO)AI?Au(AL~oVyZOeYYs0Hzu0<&KX+dHu zII`n9$+ZC9o>I=0SrFKolm)dZsEWim&+}#Jg@;tP^fX2~Evlw~fH+-vVaQdfr1v4u zi&!_11YOu8dhKW-@wiBY*>3Me@1Ul87bywpXx@b0B_6NUtxJQz9s8pKzW`lgS zku_WND-Eovb06bs=x~Q&Eg;u^RLj*i(V2`k4rsd(&FG4wd3CnhNM4=Y%P3~_E+goW zYCn2@l}&Vj7SHnBZC+MlM^+otN|4J+BV4I{ALCsn*Bu7G0pIql&GfwmM8`st;7$-s`tSR1rptX6Y4N+&jt;(H_^di^F|RlHn1 zxTbPd@nSsU8jUsOOcBNpRNjxUDHE*9B|E*H-oZCDB)G)m2k!gbxFi&`r!z0CDR4qT z0}G%XOB`REAzS0##fxg}$TrrFSyYu19X^_y)JrH=<&cBk%id0~x3hP!ySMw7C7kl5 zNz%weE6~D=OwXYVZRha6_(`FN_m9U8Dq9$86 zUZ2GjtUyPH2i!ty&us5lL@e44nFk?leajnXz&cu28F8<-ySJKn`+X8_6Wqy(pugQg z=$ZQMdGK6Uco5<_y6Gl2&Tf`?b&B|^EcV6evI%aoAuRF^9Oc1i&s7(BrH7=T-|WV@ z%O_@)!(R0ES6fYgHze8wqs4Sa5+cNav*DVX1O`H?Ahc&RTMa?I2O;De+az>$^L$pM zW$ki#u$nCUy%1>?PV;Hgbi2wGkMm8?fi8sXM|5@mrn;Yc{syrT!WN_}y&5@8fh!@Tqso@YnUHKseHsd{ZnXqoXG0Pb zdCr(Tp}a6AHDhl|BhHva5#?~H&5A2Zn+5g<(~d$5o!EAkuBc5uTi@sCUn}q7KoePH z$bI+;w~y@VKk;oJ?e5eoY>?YPPiu3u+IJVOK_K+>m+t;A-DieS3!RbNZ~sn2^4w?- zNhi^X(-4CUF({eM^G8ov;y`h(~ z*GEHVFGb#mB27+{C}q@Y7m_J$Lm4Nkm*!xPWSsQS)Ay-f6woi-cdsvg>29H4y2oes zucM#LAKx7h%$xtYIzRoT`>b2v$GXL5fwrM&{MPk|S7MKw~pbZ<6=p%nx znB=E5hD6>FlAt|B(!Il-bvkdwCCJCUTt4m{?i2~4Uo0Yq9x~I|2^H6G6d_3Tjzthv zT{g8WTB;~w2{Oe|Uj8mjLBRvWQ>S9{d*!m2;1Zi{hV{%LruQ?#oefBn@qqAuh`=Spl?+WVk95L46yg+zAWUk- z>F&>AbYN>+A zZAeI@B_R%FhGUc#h~7|9pAm*vCMBmb1hue$(pe&DtPjWPECp1c5ho-X;^B>D3dy1K2k2|?Ue^~h}vX|pgD#sNsJ zDGB`Vj-D4LfzgZV)hObndjh$0pJd-(HVMq3_~Qu)uZu2!BWJHn4gtSJQ6QH}Xu_m~ zQx;j>SAEgvvM^Qs0=QBk;pB$fZOucj|<9Hm9_umG4cV zq2u<=Eqiv~sD*M?@eh@hGrRmXm}OmCu8;*+uWgF3HhYZL;v-LqDiG&&G4ZKAA8%5n zPFX}pbDd~YxAT5v@Dd-|$^|JnQ2=QeI6@!#kC6)0ByHrAfV&~~y(xh_}bNRF*t zKUkI=*WGgK0&zeR(GZvgW+cnm{O?!jZoFoOFNx9Jhxkh(4xWuhqu=e#c4=y@HB=q6 zO!r3bL`n9fjorIJ-p_enI~E~bc;7ih&uVC%ZIr!5YwWtSN&2SHnGS67w;N+R0Q|OA zE))`s$xoP^X7baCC6UsIaGD@|tH|!P81gk!xYwDNR{K;6j@jn8-(zMqlfZ6Q+FHmj zOIeP1|2Ev`OQ{ORLxwhxa+6g}egdvkH#HfK9cz}NTQ;7){6);x30Tuu9@N4)+zpd@ z<*U}nyJ;#xt2ohRd8TS%u6fzj(m@mE+OVuqOFtLxuN5<`3Oenuog0ohJiv$tl+$12 zWFdi;(r@c;;CMV81Ra1#KaHn@V^(Q25hf~uLvvzJw{l{0E=y5R5x0xiDP(_yPeBbT zSAeFk<#pdRjG$df)nHz$6tq`DRPF}gd|vMvtD&rgQjjkwX(2vOzZbwBfBp3~h*3dJ zRDPy{iy!AqcuuUZPoE)5ur9R(ox-}a7<2#&Rv!ch0se%}?wf7O?7 z_^0=x779}8CcyQ83LhDfO!u5*+JyHM`6hO_{B4@}!fmQO?T5OvleSXN`vquG70 zFJXjF??)w+fdNB;mnSt#k^&=|K~~@~rUZs`cL7kjYO89@0wm2fGd}dicB?z*<#kJ2 z@;tnkHu<>Sxo*ArgvJSC4yf~ZSw zKjhMJYo@7cQ5+??Cks&vvyuv?le1->%(Af|M<}HC^|p2^a=|RoWA7rG9_;noMKpCV zK81|M6J0pUms?;zD4*7_yzM<+I2s&)ee^=XL>CBf$C7rU61y0dT)RCC zOM{MK$w`y%6YCM(T+(HN5j?nT^Oe8}x$T;u{2(LhRA}|3<42v?jT(bn>rC>EF zIe2#hH%2YJwlzT92=Y@WOZm^Wu5_svx1&7s?dns0_i27 zLLfNXkV5P;Ea!*Y;~-|cQ~Y1SiBoB>cEJhoWVolX5q$~nX>0^YJt#GThvUVns&5?< zo{JJZY!Rokrwq0X4be91o3fg|+w@Q@NOp90~ZD3U&SRq;&sg0~}I|i}|ePHoR>&~P- z(WefAD~DbTi>`)xRcYn;_ZHthWbVo!{)wlN|tB7rfU zp@LsyK?B-2CUW^urMcdqJy5uGs_sG38uHy&EE|B_7i0n(g7O*x(lV5KV~+A(*iXVoCCWR^)Y7M=QdWn z@R`vv^!RziK0bf{_U!G;XYBMHd;9K!oxFPf_T>w9@#^fHoxixaID7k&eLTB(#hzbW zJU@B$;*|aL?)8T^FU}8d&YKwtYJnZOXvZZBB`t`~AGxgiEPI}n&Kfhbw?%jELV#|<)1X7E5C5`NaXZs$))*s{_m6llpceZ?7YIU4A} zCY}PUQ{r|N*g=3vo!R1&z?aYsUT0p=BN*Ewet6W}q3f~;v}`)?dXCmg(fCiL6+pp| zIx~*KfTwak7qC^Jct(`BB$W9>w7w)uAxaKqib}V4uUGPr!c7!V?~ZIi@u%DyJn$(f z1e*-)Jq-%DWv`@r*yEDB){`-6xje4{#4>jso(o<#Mz9;u6WnNXHDW(BME20u0E*>1Yw|TV113)eUZP;XE-2uNz0Yj#5Z=1aXmIpy= zJ(9=TPSMvNJ&3%Cc7t_1G2W)r<^6w8gZZ|Tpn2a5ba(|1tK8Ww-c)SD(l#4dJsR24 zoubY&?CjOIMqJ+ZC@j&eZYa?wFH3e~WG&LlHc$l0D^vjfXa_;SUQ_YIJlwA`Zh%_G zBFNJLwj3@6FNU8!eHzKtVmiR0+>e5&0)JZhIoLGtXQ)DrLF1)hH{7C^m=whkRNDe^ zp7xJdu#OH#(K8JSKVFN?IVWnpqaWMDvc$;TAqP}UbYUU0$)qXEu5fvdj36}z^#Nu~ zan0Auo7e_Yc3|DBKK{AVg^jFPJNb0ZQd+E;9V0VG>}1K+0u?R}p0YEgV+}oj3FpDV zUID7T?n=D5;-IPqId=m7urk656+PuqUJQSNjixO(cDrs>hf%RmN^&`G9OjEbG_iS;LhrKNZ<1CR>c$7 zx2fMVKZyhal>=xC&yIoP<@1`jDde zo^VZFzK}uK9kh8AEwLBB6L>u|BY?pa+wsf!MPEKFEF=FDfP_^!$eVo!{wz8bRTGS1R`Xp+_@+n zi8)y%!B&EPCeY(f&+KN|d=F5*C+2N8So+p`0CNXl=tAG9QezoU-Umv);8I0jA6xUf z0VbIHL}&BF5FgZf=Mcz!B3Ad=-5|& zN;1W*aae!+WI9-*VEGAJjoC_YWn-;UNQwdrheS}MAGVd4xsCR%&qjsCiB?t?!uWwg zFhr!yj>Pqjg7r&%RZ`Lb6S+J_^@UWmaLsXp1~CrSH+B&HdK_2sP6-Os6ZP7KvlYK( zO5nqA8EZ>Nh_{vA*&}c^5BicAQFt=>U{lWsODbYV&~>v|1~0a?fH(&J)h`RJ9f{vt z8quxGLfCrE=B#er{~1>~L!nEOJz5z%!0!pGdPa00JRY&m6`7-?NEbp0W87p>8iG9o}QHnifZLEZyIQj}`qMjLnj525^D7xegb z+h_I378+aX1vtf|^z^k}u=r!{7URB^?i)Q%QeoM3B%-$!)mC>hsjR_4ywnSz4sDif zT{ej`HP?eQWzk^5m7EQZ+2BWB^V0p#3uCl#|MQU><^Btuj@jT;Ts8~$KNp72#Ng;q zX((X)9i9G&&!04A(eLT!1%cRNgOE{+RizC#vP|@59IPYmQ*AN5sR{nT(G&gPnxRd* zkIrT%=-2H;0z2cSFc>{se351RBQG;*%wlT_wk_DB7oRF&Boucqk2WVH#ei6m3S&!> z|9!^BESbi}6*&5mJ-EYQwMb;&nGZY>pDLlOgu3iA-dK?)r7(hgqXSQi{T8AQ72Gdx zcUaS4*Cdeba}1}5MNv1Mp*Gc$tLNSk8UrTi%-+E_Q6LXP62eYdVz)aiE2jPE{-p|f z*O@j(*h;G+nEP@kV_WkCyho$B(u{i}^Po12INH|x-XpnVW`KtPJjJWNMUVV1I#K=c zLk{k4ayy@q!aMgnP)RlPmjK{b8$O@Q*@(TSQuNZY%aW@rANAV8M&Fsn?71F!NC<{x z;VVq?c=Y;kq^splZjTvv3{P}Q?RqPa8Q-%kWl1;4tHvE}K^<~Tqm0(WmOZ&Ppj8K- znw)89ssbwR6XQsp0d1$0eNmy4l6fNzpeMXqoM<(dW(B&+A4^Cr9z1if1xuSSYLg>| z`?2L5&Sx|5;pHW36y>cAcB(9U?ftNQm&XFNBScg$&I?>QZOHyuFR>EP*jI`Go?S|RN_5{>tO8gg$DV&83smVeM4 zBJDD9&=Cr|vxGkd1jTHts2oyyfc_cO_>MNJr;?4EeYU!s4A=&r78EKNA zy+LudT8TpP8Z&o*OyFVStr8Jhq47GnVeSqREl#4tNTLA!^C6uwKZA=yx(&dw99SgOoZx2R69`Al*$IUi_#Jbj5p5iUL}<;x3(m zYmV`kt<365ej3h+vz|w#K+FHk*na4(&61! z++3w*L1(WW*Q8Vy`u z4aP@k0G3Al*4cB{#^~f2&>R}Ui^Ll&cLi%y)a{e!*PRYJ=_@IhM(0`LE} z4-9hGa*VT0g7#YgsVD*$40j1k9%lc5mM6L_#mxQS=lNjyLc9^Rku&>6%L^s8PJE** zWGM_C_ES~lS=(@U#+6pLE8RF^4K_5#K{y<#j4qm4?YJ+auLTAqHKx+mk?SbW3RPG? znjn6fh|1r+&HO#;JB0biqh(!J_SsioEo8lHE=M!HiivQ^lrc2E`4Lg0V+zri3711! zm9~66X)a4S^Dttk+%7LQHw6nbukcfvdie;cW@ouHeKejU{@@-He@maOK7^Dak+sKE zC<%W>ws2#kZT7+qo^7WjgT0bxG zO6~68zV9di+KL@9gtQD`j8j!pf2EtcYHIfA?A=l7(2M$*e>TzxG!CN@owBfv*mDcs zQ5K@6B}fPsEU1sibzCLxk81z<4C&xL5cad?V&@0^XhP`xBck)sq4?+YuD@y)qT&nD;u^MGd_bVK zTFB?b6l_I2)UsI!RzYr9`B|_>Qn5GkhofK^&u2LpP}&^xlkwMEv}SrfFQbz2eGs`4 zlLoeE%X6M#-9{C2DUPP=Ped9eyMu#=Zcq^_g=J2~iA(X2k&H)qw6nC@5wM|6R$NXP zD{U>*O!!2iKJc;YYPh$&k>&^P&l)=TqLZ4`zb$?p9VliEb^)2cck4E8#H{3U72MWa zHX5AgJ>>d|zU}R#f-r>lF((DRzLuC!#MTBMFq@OnG*BA#da||*hXV2o-X29>=Lc7U z<$N$L5!Lg#Kcsq*3+Eu*!pU>Y@(p%DtX6{H9ZEsn4}m%vhxY(ducQ+TStS{Ix9q%C zvZ9q%H;WV7Y10`x_}h*Mk!0H^tk?*hcCn1Tq0@^od0zi^1%Pd)f!5UwF5o^z#|SCe z9U0s#pJB|?fi6tzacmF3uJ3aJEcnqCP%e#H%6iCP$k-!IS!;2Hb*@4pTdUx~r90V-++$7~?& zOLrWDXKw$${o`ly23kY6`ykH3miIW=O_jj5P=GW)&;9T>Pq^cmv+YFkKnR?r4|*uP z?E|8XYglvg?WMNS`|TYd*$P91__0=5t5Bkl)qG*Is!R0J7rf>X$L%xb)0!X8xvkgw zwjCBRQ^)r^U?k>H&;8TEQ}~b=*#Bl_Zuk#{f*H6}Z-V?Uf5@QG3J{G3Ta-I9l(3s% zhe`#db7&)7O^QckOn0Ig48EI@!1g#GgLhC;@jIJqw1K|nK@p*Jz=5!L#{=<+Do@C~ z)^j*7s0llN^?dlv<0qLZu8qlF^R(_r`d#;_4o*H4R)HtAX{=sq!_|`3*PO86^e@$- z6gKhRKdWQb<(Xcsgrc%^)~DB{{`3B`2WJ-XsnVt%&W&CT5$C3Z-H$Z|o`YQm=Z8IN zx4m=N-NkLycMDJ3`@h5a_8%oxcgwRJcMH)b%EMZ-YhnDY#Jki#c2KRuBs~QSwGxT8 zAwDwg<9=A&e2x!XKI|-u81CTXbkJ0#<{+?OagG*V7f`h0T5|T`EKB#2Rn}MvBS!2) z<)fv7#u03|IIBSCQc{oxn7ZW(RV0z$lnKPIJkfhY7%b@`B8;)jaOj7IC>eF5A zexm?O5sz6wcE-a|0ridUIH@#U}6L1W74;MsKGZDBO)5M~{c2lB{19U8HaT8;RM zf7XiMSTNMpPM*!WOb5Sx`Sa0(-n<_Kn{gxNP3d(8ByPdI7~BO9TZi^LGoZV`ub1i2AZA(di z%8}_M)}3a&heY6^u++9yy>3{wso4A*)Iwbxl;{KGfJ<~l6t^T9aU`% z=jw&$tJt}3=~b*0?3eyk->Nmm9O-RRk3Pv*!!B>xT)S)O`ILDBk$Q0m_Uo^1 zcfbAiZ@>QP{{HQ^(Ha7>e&1&_9uz%J_h=DIMvWZR_@>59zUOMT6lORv`qOQnH3PaL zhvG;=nusSO0~Eq@Mg{fX>OxFF+v@&uN8wKbf63-00|+Zz?&4TT2ff{XmUQWM@ctU8F?*B zktIHbP#!0rLgJ*&nXpKTip~m2c+%t1lW*W01UIF0qL%w3DB2)r;Sg+c1v~d^<;6-` zN>CPRPWX8Im$b`|}Qjkoe@LkjFUV(Tvx1DMmL^75c`$0cy|;l`oIGjLV$ zy8}`etAWADpapTQ0YJ7 zHn=y@!Zw&|FBh(v5hxx#hJ7!%wCExvwemT>LuOV?0}*ntasO!35l|^k|2AX~;MG%$ zPn)?CPs0B_rnfDnerxdNd-tIK=}+y4$GaJHMB4~fH{+ly?!x=$)-cHae3JZm_0(<) z^G-c&ULGbx3Ba-Ap3^ZzB-wV#QqHPo$FwA!Df6@>>s-**1?WG1^3Av}Ey>Ww)KNx8 z=%D9p95X}asYxI-wJ#$H@Q)b4;01OS(uer>_pyI|zZ;LoBbG*@g5zMG*I~roKs{g2 zaZ==ik&A_UR(Mie%;$FSjQE;0o@$^bNts|A^JXc_nC*ib!EBA$jL{cx*Qoq2*YOjN pGj`&;al6j7JD>me$G<=R{qgUQe{28!PXGV_|Nrm8LJ= 1.23.0-0' + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/permits-os: linux,windows + catalog.cattle.io/provides-gvr: longhorn.io/v1beta1 + catalog.cattle.io/rancher-version: '>= 2.10.0-0 < 2.11.0-0' + catalog.cattle.io/release-name: longhorn + catalog.cattle.io/type: cluster-tool + catalog.cattle.io/upstream-version: 1.6.4 +apiVersion: v1 +appVersion: v1.6.4 +description: Longhorn is a distributed block storage system for Kubernetes. +home: https://github.com/longhorn/longhorn +icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/longhorn/icon/color/longhorn-icon-color.png +keywords: +- longhorn +- storage +- distributed +- block +- device +- iscsi +- nfs +maintainers: +- email: maintainers@longhorn.io + name: Longhorn maintainers +name: longhorn +sources: +- https://github.com/longhorn/longhorn +- https://github.com/longhorn/longhorn-engine +- https://github.com/longhorn/longhorn-instance-manager +- https://github.com/longhorn/longhorn-share-manager +- https://github.com/longhorn/longhorn-manager +- https://github.com/longhorn/longhorn-ui +- https://github.com/longhorn/longhorn-tests +- https://github.com/longhorn/backing-image-manager +version: 105.0.1+up1.6.4 diff --git a/charts/longhorn/105.0.1+up1.6.4/README.md b/charts/longhorn/105.0.1+up1.6.4/README.md new file mode 100644 index 0000000000..adb190be3b --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/README.md @@ -0,0 +1,50 @@ +# Longhorn Chart + +> **Important**: Please install the Longhorn chart in the `longhorn-system` namespace only. + +> **Warning**: Longhorn doesn't support downgrading from a higher version to a lower version. + +> **Note**: Use Helm 3 when installing and upgrading Longhorn. Helm 2 is [no longer supported](https://helm.sh/blog/helm-2-becomes-unsupported/). + +## Source Code + +Longhorn is 100% open source software. Project source code is spread across a number of repos: + +1. Longhorn Engine -- Core controller/replica logic https://github.com/longhorn/longhorn-engine +2. Longhorn Instance Manager -- Controller/replica instance lifecycle management https://github.com/longhorn/longhorn-instance-manager +3. Longhorn Share Manager -- NFS provisioner that exposes Longhorn volumes as ReadWriteMany volumes. https://github.com/longhorn/longhorn-share-manager +4. Backing Image Manager -- Backing image file lifecycle management. https://github.com/longhorn/backing-image-manager +5. Longhorn Manager -- Longhorn orchestration, includes CSI driver for Kubernetes https://github.com/longhorn/longhorn-manager +6. Longhorn UI -- Dashboard https://github.com/longhorn/longhorn-ui + +## Prerequisites + +1. A container runtime compatible with Kubernetes (Docker v1.13+, containerd v1.3.7+, etc.) +2. Kubernetes >= v1.21 +3. Make sure `bash`, `curl`, `findmnt`, `grep`, `awk` and `blkid` has been installed in all nodes of the Kubernetes cluster. +4. Make sure `open-iscsi` has been installed, and the `iscsid` daemon is running on all nodes of the Kubernetes cluster. For GKE, recommended Ubuntu as guest OS image since it contains `open-iscsi` already. + +## Upgrading to Kubernetes v1.25+ + +Starting in Kubernetes v1.25, [Pod Security Policies](https://kubernetes.io/docs/concepts/security/pod-security-policy/) have been removed from the Kubernetes API. + +As a result, **before upgrading to Kubernetes v1.25** (or on a fresh install in a Kubernetes v1.25+ cluster), users are expected to perform an in-place upgrade of this chart with `enablePSP` set to `false` if it has been previously set to `true`. + +> **Note:** +> If you upgrade your cluster to Kubernetes v1.25+ before removing PSPs via a `helm upgrade` (even if you manually clean up resources), **it will leave the Helm release in a broken state within the cluster such that further Helm operations will not work (`helm uninstall`, `helm upgrade`, etc.).** +> +> If your charts get stuck in this state, you may have to clean up your Helm release secrets. +Upon setting `enablePSP` to false, the chart will remove any PSP resources deployed on its behalf from the cluster. This is the default setting for this chart. + +As a replacement for PSPs, [Pod Security Admission](https://kubernetes.io/docs/concepts/security/pod-security-admission/) should be used. Please consult the Longhorn docs for more details on how to configure your chart release namespaces to work with the new Pod Security Admission and apply Pod Security Standards. + +## Uninstallation + +To prevent Longhorn from being accidentally uninstalled (which leads to data lost), we introduce a new setting, deleting-confirmation-flag. If this flag is **false**, the Longhorn uninstallation job will fail. Set this flag to **true** to allow Longhorn uninstallation. You can set this flag using setting page in Longhorn UI or `kubectl -n longhorn-system patch -p '{"value": "true"}' --type=merge lhs deleting-confirmation-flag` + +To prevent damage to the Kubernetes cluster, we recommend deleting all Kubernetes workloads using Longhorn volumes (PersistentVolume, PersistentVolumeClaim, StorageClass, Deployment, StatefulSet, DaemonSet, etc). + +From Rancher Cluster Explorer UI, navigate to Apps page, delete app `longhorn` then app `longhorn-crd` in Installed Apps tab. + +--- +Please see [link](https://github.com/longhorn/longhorn) for more information. diff --git a/charts/longhorn/105.0.1+up1.6.4/app-readme.md b/charts/longhorn/105.0.1+up1.6.4/app-readme.md new file mode 100644 index 0000000000..321e5193c4 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/app-readme.md @@ -0,0 +1,27 @@ +# Longhorn + +Longhorn is a lightweight, reliable and easy to use distributed block storage system for Kubernetes. Once deployed, users can leverage persistent volumes provided by Longhorn. + +Longhorn creates a dedicated storage controller for each volume and synchronously replicates the volume across multiple replicas stored on multiple nodes. The storage controller and replicas are themselves orchestrated using Kubernetes. Longhorn supports snapshots, backups and even allows you to schedule recurring snapshots and backups! + +**Important**: Please install Longhorn chart in `longhorn-system` namespace only. + +**Warning**: Longhorn doesn't support downgrading from a higher version to a lower version. + +[Chart Documentation](https://github.com/longhorn/longhorn/blob/master/chart/README.md) + + +## Upgrading to Kubernetes v1.25+ + +Starting in Kubernetes v1.25, [Pod Security Policies](https://kubernetes.io/docs/concepts/security/pod-security-policy/) have been removed from the Kubernetes API. + +As a result, **before upgrading to Kubernetes v1.25** (or on a fresh install in a Kubernetes v1.25+ cluster), users are expected to perform an in-place upgrade of this chart with `enablePSP` set to `false` if it has been previously set to `true`. + +> **Note:** +> If you upgrade your cluster to Kubernetes v1.25+ before removing PSPs via a `helm upgrade` (even if you manually clean up resources), **it will leave the Helm release in a broken state within the cluster such that further Helm operations will not work (`helm uninstall`, `helm upgrade`, etc.).** +> +> If your charts get stuck in this state, please consult the Rancher docs on how to clean up your Helm release secrets. + +Upon setting `enablePSP` to false, the chart will remove any PSP resources deployed on its behalf from the cluster. This is the default setting for this chart. + +As a replacement for PSPs, [Pod Security Admission](https://kubernetes.io/docs/concepts/security/pod-security-admission/) should be used. Please consult the Rancher docs for more details on how to configure your chart release namespaces to work with the new Pod Security Admission and apply Pod Security Standards. \ No newline at end of file diff --git a/charts/longhorn/105.0.1+up1.6.4/questions.yaml b/charts/longhorn/105.0.1+up1.6.4/questions.yaml new file mode 100644 index 0000000000..3604f134a7 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/questions.yaml @@ -0,0 +1,908 @@ +categories: +- storage +namespace: longhorn-system +questions: +- variable: image.defaultImage + default: "true" + description: "Use default Longhorn images" + label: Use Default Images + type: boolean + show_subquestion_if: false + group: "Longhorn Images" + subquestions: + - variable: image.longhorn.manager.repository + default: rancher/mirrored-longhornio-longhorn-manager + description: "Repository for the Longhorn Manager image." + type: string + label: Longhorn Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.manager.tag + default: v1.6.4 + description: "Specify Longhorn Manager Image Tag" + type: string + label: Longhorn Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.engine.repository + default: rancher/mirrored-longhornio-longhorn-engine + description: "Repository for the Longhorn Engine image." + type: string + label: Longhorn Engine Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.engine.tag + default: v1.6.4 + description: "Specify Longhorn Engine Image Tag" + type: string + label: Longhorn Engine Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.ui.repository + default: rancher/mirrored-longhornio-longhorn-ui + description: "Repository for the Longhorn UI image." + type: string + label: Longhorn UI Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.ui.tag + default: v1.6.4 + description: "Specify Longhorn UI Image Tag" + type: string + label: Longhorn UI Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.instanceManager.repository + default: rancher/mirrored-longhornio-longhorn-instance-manager + description: "Repository for the Longhorn Instance Manager image." + type: string + label: Longhorn Instance Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.instanceManager.tag + default: v1.6.4 + description: "Specify Longhorn Instance Manager Image Tag" + type: string + label: Longhorn Instance Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.shareManager.repository + default: rancher/mirrored-longhornio-longhorn-share-manager + description: "Repository for the Longhorn Share Manager image." + type: string + label: Longhorn Share Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.shareManager.tag + default: v1.6.4 + description: "Specify Longhorn Share Manager Image Tag" + type: string + label: Longhorn Share Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.backingImageManager.repository + default: rancher/mirrored-longhornio-backing-image-manager + description: "Repository for the Backing Image Manager image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn Backing Image Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.backingImageManager.tag + default: v1.6.4 + description: "Specify Longhorn Backing Image Manager Image Tag" + type: string + label: Longhorn Backing Image Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.supportBundleKit.repository + default: rancher/mirrored-longhornio-support-bundle-kit + description: "Repository for the Longhorn Support Bundle Manager image." + type: string + label: Longhorn Support Bundle Kit Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.supportBundleKit.tag + default: v0.0.48 + description: "Tag for the Longhorn Support Bundle Manager image." + type: string + label: Longhorn Support Bundle Kit Image Tag + group: "Longhorn Images Settings" + - variable: image.csi.attacher.repository + default: rancher/mirrored-longhornio-csi-attacher + description: "Repository for the CSI attacher image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Attacher Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.attacher.tag + default: v4.7.0-20241219 + description: "Tag for the CSI attacher image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Attacher Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.provisioner.repository + default: rancher/mirrored-longhornio-csi-provisioner + description: "Repository for the CSI Provisioner image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Provisioner Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.provisioner.tag + default: v3.6.4-20241219 + description: "Tag for the CSI Provisioner image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Provisioner Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.nodeDriverRegistrar.repository + default: rancher/mirrored-longhornio-csi-node-driver-registrar + description: "Repository for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Node Driver Registrar Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.nodeDriverRegistrar.tag + default: v2.12.0-20241219 + description: "Tag for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Node Driver Registrar Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.resizer.repository + default: rancher/mirrored-longhornio-csi-resizer + description: "Repository for the CSI Resizer image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Resizer Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.resizer.tag + default: v1.12.0-20241219 + description: "Tag for the CSI Resizer image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Resizer Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.snapshotter.repository + default: rancher/mirrored-longhornio-csi-snapshotter + description: "Repository for the CSI Snapshotter image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Snapshotter Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.snapshotter.tag + default: v6.3.4-20241219 + description: "Tag for the CSI Snapshotter image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Snapshotter Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.livenessProbe.repository + default: rancher/mirrored-longhornio-livenessprobe + description: "Repository for the CSI liveness probe image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Liveness Probe Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.livenessProbe.tag + default: v2.14.0-20241219 + description: "Tag for the CSI liveness probe image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Liveness Probe Image Tag + group: "Longhorn CSI Driver Images" +- variable: privateRegistry.registryUrl + label: Private registry URL + description: "URL of a private registry. When unspecified, Longhorn uses the default system registry." + group: "Private Registry Settings" + type: string + default: "" +- variable: privateRegistry.registrySecret + label: Private registry secret name + description: "Kubernetes secret that allows you to pull images from a private registry. This setting applies only when creation of private registry secrets is enabled. You must include the private registry name in the secret name." + group: "Private Registry Settings" + type: string + default: "" +- variable: privateRegistry.createSecret + default: "true" + description: "Setting that allows you to create a private registry secret." + type: boolean + group: "Private Registry Settings" + label: Create Secret for Private Registry Settings + show_subquestion_if: true + subquestions: + - variable: privateRegistry.registryUser + label: Private registry user + description: "User account used for authenticating with a private registry." + type: string + default: "" + - variable: privateRegistry.registryPasswd + label: Private registry password + description: "Password for authenticating with a private registry." + type: password + default: "" +- variable: longhorn.default_setting + default: "false" + description: "Customize the default settings before installing Longhorn for the first time. This option will only work if the cluster hasn't installed Longhorn." + label: "Customize Default Settings" + type: boolean + show_subquestion_if: true + group: "Longhorn Default Settings" + subquestions: + - variable: csi.kubeletRootDir + default: + description: "kubelet root directory. When unspecified, Longhorn uses the default value." + type: string + label: Kubelet Root Directory + group: "Longhorn CSI Driver Settings" + - variable: csi.attacherReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Attacher. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Attacher replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.provisionerReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Provisioner. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Provisioner replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.resizerReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Resizer. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Resizer replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.snapshotterReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Snapshotter. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Snapshotter replica count + group: "Longhorn CSI Driver Settings" + - variable: defaultSettings.backupTarget + label: Backup Target + description: "Endpoint used to access the backupstore. (Options: \"NFS\", \"CIFS\", \"AWS\", \"GCP\", \"AZURE\")" + group: "Longhorn Default Settings" + type: string + default: + - variable: defaultSettings.backupTargetCredentialSecret + label: Backup Target Credential Secret + description: "Name of the Kubernetes secret associated with the backup target." + group: "Longhorn Default Settings" + type: string + default: + - variable: defaultSettings.allowRecurringJobWhileVolumeDetached + label: Allow Recurring Job While Volume Is Detached + description: 'Setting that allows Longhorn to automatically attach a volume and create snapshots or backups when recurring jobs are run.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.snapshotMaxCount + label: Snapshot Maximum Count + description: 'Maximum snapshot count for a volume. The value should be between 2 to 250.' + group: "Longhorn Default Settings" + type: int + min: 2 + max: 250 + default: 250 + - variable: defaultSettings.createDefaultDiskLabeledNodes + label: Create Default Disk on Labeled Nodes + description: 'Setting that allows Longhorn to automatically create a default disk only on nodes with the label "node.longhorn.io/create-default-disk=true" (if no other disks exist). When this setting is disabled, Longhorn creates a default disk on each node that is added to the cluster.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.defaultDataPath + label: Default Data Path + description: 'Default path for storing data on a host. The default value is "/var/lib/longhorn/".' + group: "Longhorn Default Settings" + type: string + default: "/var/lib/longhorn/" + - variable: defaultSettings.defaultDataLocality + label: Default Data Locality + description: 'Default data locality. A Longhorn volume has data locality if a local replica of the volume exists on the same node as the pod that is using the volume.' + group: "Longhorn Default Settings" + type: enum + options: + - "disabled" + - "best-effort" + default: "disabled" + - variable: defaultSettings.replicaSoftAntiAffinity + label: Replica Node Level Soft Anti-Affinity + description: 'Allow scheduling on nodes with existing healthy replicas of the same volume. By default, false.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.replicaAutoBalance + label: Replica Auto Balance + description: 'Enable this setting automatically re-balances replicas when discovered an available node.' + group: "Longhorn Default Settings" + type: enum + options: + - "disabled" + - "least-effort" + - "best-effort" + default: "disabled" + - variable: defaultSettings.storageOverProvisioningPercentage + label: Storage Over Provisioning Percentage + description: "Percentage of storage that can be allocated relative to hard drive capacity. The default value is 100." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 100 + - variable: defaultSettings.storageMinimalAvailablePercentage + label: Storage Minimal Available Percentage + description: "If the minimum available disk capacity exceeds the actual percentage of available disk capacity, the disk becomes unschedulable until more space is freed up. By default, 25." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 100 + default: 25 + - variable: defaultSettings.storageReservedPercentageForDefaultDisk + label: Storage Reserved Percentage For Default Disk + description: "The reserved percentage specifies the percentage of disk space that will not be allocated to the default disk on each new Longhorn node." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 100 + default: 30 + - variable: defaultSettings.upgradeChecker + label: Enable Upgrade Checker + description: 'Upgrade Checker that periodically checks for new Longhorn versions. When a new version is available, a notification appears on the Longhorn UI. This setting is enabled by default.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.defaultReplicaCount + label: Default Replica Count + description: "Default number of replicas for volumes created using the Longhorn UI. For Kubernetes configuration, modify the `numberOfReplicas` field in the StorageClass. The default value is \"3\"." + group: "Longhorn Default Settings" + type: int + min: 1 + max: 20 + default: 3 + - variable: defaultSettings.defaultLonghornStaticStorageClass + label: Default Longhorn Static StorageClass Name + description: "Default Longhorn StorageClass. \"storageClassName\" is assigned to PVs and PVCs that are created for an existing Longhorn volume. \"storageClassName\" can also be used as a label, so it is possible to use a Longhorn StorageClass to bind a workload to an existing PV without creating a Kubernetes StorageClass object. The default value is \"longhorn-static\"." + group: "Longhorn Default Settings" + type: string + default: "longhorn-static" + - variable: defaultSettings.backupstorePollInterval + label: Backupstore Poll Interval + description: "Number of seconds that Longhorn waits before checking the backupstore for new backups. The default value is \"300\". When the value is \"0\", polling is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 300 + - variable: defaultSettings.failedBackupTTL + label: Failed Backup Time to Live + description: "Number of minutes that Longhorn keeps a failed backup resource. When the value is \"0\", automatic deletion is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1440 + - variable: defaultSettings.restoreVolumeRecurringJobs + label: Restore Volume Recurring Jobs + description: "Restore recurring jobs from the backup volume on the backup target and create recurring jobs if not exist during a backup restoration." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.recurringSuccessfulJobsHistoryLimit + label: Cronjob Successful Jobs History Limit + description: "This setting specifies how many successful backup or snapshot job histories should be retained. History will not be retained if the value is 0." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.recurringFailedJobsHistoryLimit + label: Cronjob Failed Jobs History Limit + description: 'Maximum number of failed recurring backup and snapshot jobs to be retained. When the value is "0", a history of failed recurring jobs is not retained.' + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.recurringJobMaxRetention + label: Maximum Retention Number for Recurring Job + description: "Maximum number of snapshots or backups to be retained." + group: "Longhorn Default Settings" + type: int + default: 100 + - variable: defaultSettings.supportBundleFailedHistoryLimit + label: SupportBundle Failed History Limit + description: "This setting specifies how many failed support bundles can exist in the cluster. Set this value to **0** to have Longhorn automatically purge all failed support bundles." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.autoSalvage + label: Automatic salvage + description: "Setting that allows Longhorn to automatically salvage volumes when all replicas become faulty (for example, when the network connection is interrupted). Longhorn determines which replicas are usable and then uses these replicas for the volume. This setting is enabled by default." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly + label: Automatically Delete Workload Pod when The Volume Is Detached Unexpectedly + description: 'Setting that allows Longhorn to automatically delete a workload pod that is managed by a controller (for example, daemonset) whenever a Longhorn volume is detached unexpectedly (for example, during Kubernetes upgrades). After deletion, the controller restarts the pod and then Kubernetes handles volume reattachment and remounting.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.disableSchedulingOnCordonedNode + label: Disable Scheduling On Cordoned Node + description: "Setting that prevents Longhorn Manager from scheduling replicas on a cordoned Kubernetes node. This setting is enabled by default." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.replicaZoneSoftAntiAffinity + label: Replica Zone Level Soft Anti-Affinity + description: "Allow scheduling new Replicas of Volume to the Nodes in the same Zone as existing healthy Replicas. Nodes don't belong to any Zone will be treated as in the same Zone. Notice that Longhorn relies on label `topology.kubernetes.io/zone=` in the Kubernetes node object to identify the zone. By, default true." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.replicaDiskSoftAntiAffinity + label: Replica Disk Level Soft Anti-Affinity + description: 'Allow scheduling on disks with existing healthy replicas of the same volume. By default, true.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.allowEmptyNodeSelectorVolume + label: Allow Empty Node Selector Volume + description: "Setting that allows scheduling of empty node selector volumes to any node." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.allowEmptyDiskSelectorVolume + label: Allow Empty Disk Selector Volume + description: "Setting that allows scheduling of empty disk selector volumes to any disk." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.nodeDownPodDeletionPolicy + label: Pod Deletion Policy When Node is Down + description: "Policy that defines the action Longhorn takes when a volume is stuck with a StatefulSet or Deployment pod on a node that failed." + group: "Longhorn Default Settings" + type: enum + options: + - "do-nothing" + - "delete-statefulset-pod" + - "delete-deployment-pod" + - "delete-both-statefulset-and-deployment-pod" + default: "do-nothing" + - variable: defaultSettings.nodeDrainPolicy + label: Node Drain Policy + description: "Policy that defines the action Longhorn takes when a node with the last healthy replica of a volume is drained." + group: "Longhorn Default Settings" + type: enum + options: + - "block-for-eviction" + - "block-for-eviction-if-contains-last-replica" + - "block-if-contains-last-replica" + - "allow-if-replica-is-stopped" + - "always-allow" + default: "block-if-contains-last-replica" + - variable: defaultSettings.detachManuallyAttachedVolumesWhenCordoned + label: Detach Manually Attached Volumes When Cordoned + description: "Setting that allows automatic detaching of manually-attached volumes when a node is cordoned." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.priorityClass + label: Priority Class + description: "PriorityClass for system-managed Longhorn components. This setting can help prevent Longhorn components from being evicted under Node Pressure. Longhorn system contains user deployed components (E.g, Longhorn manager, Longhorn driver, Longhorn UI) and system managed components (E.g, instance manager, engine image, CSI driver, etc.) Note that this will be applied to Longhorn user-deployed components by default if there are no priority class values set yet, such as `longhornManager.priorityClass`. WARNING: DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES." + group: "Longhorn Default Settings" + type: string + default: "longhorn-critical" + - variable: defaultSettings.replicaReplenishmentWaitInterval + label: Replica Replenishment Wait Interval + description: "The interval in seconds determines how long Longhorn will at least wait to reuse the existing data on a failed replica rather than directly creating a new replica for a degraded volume." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 600 + - variable: defaultSettings.concurrentReplicaRebuildPerNodeLimit + label: Concurrent Replica Rebuild Per Node Limit + description: "Maximum number of replicas that can be concurrently rebuilt on each node. + WARNING: + - The old setting \"Disable Replica Rebuild\" is replaced by this setting. + - Different from relying on replica starting delay to limit the concurrent rebuilding, if the rebuilding is disabled, replica object replenishment will be directly skipped. + - When the value is 0, the eviction and data locality feature won't work. But this shouldn't have any impact to any current replica rebuild and backup restore." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 5 + - variable: defaultSettings.concurrentVolumeBackupRestorePerNodeLimit + label: Concurrent Volume Backup Restore Per Node Limit + description: "Maximum number of volumes that can be concurrently restored on each node using a backup. When the value is \"0\", restoration of volumes using a backup is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 5 + - variable: defaultSettings.disableRevisionCounter + label: Disable Revision Counter + description: "Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the \"volume-head-xxx.img\" file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. This setting applies only to volumes created using the Longhorn UI." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.systemManagedPodsImagePullPolicy + label: System Managed Pod Image Pull Policy + description: "Image pull policy for system-managed pods, such as Instance Manager, engine images, and CSI Driver. Changes to the image pull policy are applied only after the system-managed pods restart." + group: "Longhorn Default Settings" + type: enum + options: + - "if-not-present" + - "always" + - "never" + default: "if-not-present" + - variable: defaultSettings.allowVolumeCreationWithDegradedAvailability + label: Allow Volume Creation with Degraded Availability + description: "Setting that allows you to create and attach a volume without having all replicas scheduled at the time of creation." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoCleanupSystemGeneratedSnapshot + label: Automatically Cleanup System Generated Snapshot + description: "Setting that allows Longhorn to automatically clean up the system-generated snapshot after replica rebuilding is completed." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoCleanupRecurringJobBackupSnapshot + label: Automatically Cleanup Recurring Job Backup Snapshot + description: "Setting that allows Longhorn to automatically clean up the snapshot generated by a recurring backup job." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit + label: Concurrent Automatic Engine Upgrade Per Node Limit + description: "Maximum number of engines that are allowed to concurrently upgrade on each node after Longhorn Manager is upgraded. When the value is \"0\", Longhorn does not automatically upgrade volume engines to the new default engine image version." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 0 + - variable: defaultSettings.backingImageCleanupWaitInterval + label: Backing Image Cleanup Wait Interval + description: "Number of minutes that Longhorn waits before cleaning up the backing image file when no replicas in the disk are using it." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 60 + - variable: defaultSettings.backingImageRecoveryWaitInterval + label: Backing Image Recovery Wait Interval + description: "Number of seconds that Longhorn waits before downloading a backing image file again when the status of all image disk files changes to \"failed\" or \"unknown\"." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 300 + - variable: defaultSettings.guaranteedInstanceManagerCPU + label: Guaranteed Instance Manager CPU + description: "Percentage of the total allocatable CPU resources on each node to be reserved for each instance manager pod when the V1 Data Engine is enabled. The default value is \"12\". + WARNING: + - Value 0 means removing the CPU requests from spec of instance manager pods. + - Considering the possible number of new instance manager pods in a further system upgrade, this integer value ranges from 0 to 40. + - One more set of instance manager pods may need to be deployed when the Longhorn system is upgraded. If current available CPUs of the nodes are not enough for the new instance manager pods, you need to detach the volumes using the oldest instance manager pods so that Longhorn can clean up the old pods automatically and release the CPU resources. And the new pods with the latest instance manager image will be launched then. + - This global setting will be ignored for a node if the field \"InstanceManagerCPURequest\" on the node is set. + - After this setting is changed, all instance manager pods using this global setting on all the nodes will be automatically restarted. In other words, DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 40 + default: 12 + - variable: defaultSettings.logLevel + label: Log Level + description: 'Log levels that indicate the type and severity of logs in Longhorn Manager. The default value is "Info". (Options: "Panic", "Fatal", "Error", "Warn", "Info", "Debug", "Trace")' + group: "Longhorn Default Settings" + type: string + default: "Info" + - variable: defaultSettings.disableSnapshotPurge + label: Disable Snapshot Purge + description: "Setting that temporarily prevents all attempts to purge volume snapshots." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.kubernetesClusterAutoscalerEnabled + label: Kubernetes Cluster Autoscaler Enabled (Experimental) + description: "Setting that notifies Longhorn that the cluster is using the Kubernetes Cluster Autoscaler. + WARNING: + - Replica rebuilding could be expensive because nodes with reusable replicas could get removed by the Kubernetes Cluster Autoscaler." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.orphanAutoDeletion + label: Orphaned Data Cleanup + description: "Setting that allows Longhorn to automatically delete an orphaned resource and the corresponding data (for example, stale replicas). Orphaned resources on failed or unknown nodes are not automatically cleaned up." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.storageNetwork + label: Storage Network + description: "Longhorn uses the storage network for in-cluster data traffic. Leave this blank to use the Kubernetes cluster network. + WARNING: + - This setting should change after detaching all Longhorn volumes, as some of the Longhorn system component pods will get recreated to apply the setting. Longhorn will try to block this setting update when there are attached volumes." + group: "Longhorn Default Settings" + type: string + default: +- variable: defaultSettings.deletingConfirmationFlag + label: Deleting Confirmation Flag + description: "Flag that prevents accidental uninstallation of Longhorn." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.engineReplicaTimeout + label: Timeout between Engine and Replica + description: "Timeout between the Longhorn Engine and replicas. Specify a value between \"8\" and \"30\" seconds. The default value is \"8\"." + group: "Longhorn Default Settings" + type: int + default: "8" +- variable: defaultSettings.snapshotDataIntegrity + label: Snapshot Data Integrity + description: "This setting allows users to enable or disable snapshot hashing and data integrity checking." + group: "Longhorn Default Settings" + type: string + default: "disabled" +- variable: defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation + label: Immediate Snapshot Data Integrity Check After Creating a Snapshot + description: "Hashing snapshot disk files impacts the performance of the system. The immediate snapshot hashing and checking can be disabled to minimize the impact after creating a snapshot." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.snapshotDataIntegrityCronjob + label: Snapshot Data Integrity Check CronJob + description: "Unix-cron string format. The setting specifies when Longhorn checks the data integrity of snapshot disk files." + group: "Longhorn Default Settings" + type: string + default: "0 0 */7 * *" +- variable: defaultSettings.removeSnapshotsDuringFilesystemTrim + label: Remove Snapshots During Filesystem Trim + description: "This setting allows Longhorn filesystem trim feature to automatically mark the latest snapshot and its ancestors as removed and stops at the snapshot containing multiple children." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.fastReplicaRebuildEnabled + label: Fast Replica Rebuild Enabled + description: "Setting that allows fast rebuilding of replicas using the checksum of snapshot disk files. Before enabling this setting, you must set the snapshot-data-integrity value to \"enable\" or \"fast-check\"." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.replicaFileSyncHttpClientTimeout + label: Timeout of HTTP Client to Replica File Sync Server + description: "In seconds. The setting specifies the HTTP client timeout to the file sync server." + group: "Longhorn Default Settings" + type: int + default: "30" +- variable: defaultSettings.backupCompressionMethod + label: Backup Compression Method + description: "Setting that allows you to specify a backup compression method." + group: "Longhorn Default Settings" + type: string + default: "lz4" +- variable: defaultSettings.backupConcurrentLimit + label: Backup Concurrent Limit Per Backup + description: "Maximum number of worker threads that can concurrently run for each backup." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 2 +- variable: defaultSettings.restoreConcurrentLimit + label: Restore Concurrent Limit Per Backup + description: "This setting controls how many worker threads per restore concurrently." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 2 +- variable: defaultSettings.allowCollectingLonghornUsageMetrics + label: Allow Collecting Longhorn Usage Metrics + description: "Setting that allows Longhorn to periodically collect anonymous usage data for product improvement purposes. Longhorn sends collected data to the [Upgrade Responder](https://github.com/longhorn/upgrade-responder) server, which is the data source of the Longhorn Public Metrics Dashboard (https://metrics.longhorn.io). The Upgrade Responder server does not store data that can be used to identify clients, including IP addresses." + group: "Longhorn Default Settings" + type: boolean + default: true +- variable: defaultSettings.v1DataEngine + label: V1 Data Engine + description: "Setting that allows you to enable the V1 Data Engine." + group: "Longhorn V1 Data Engine Settings" + type: boolean + default: true +- variable: defaultSettings.v2DataEngine + label: V2 Data Engine + description: "Setting that allows you to enable the V2 Data Engine, which is based on the Storage Performance Development Kit (SPDK). The V2 Data Engine is a preview feature and should not be used in production environments. + WARNING: + - DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES. Longhorn will block this setting update when there are attached volumes. + - When the V2 Data Engine is enabled, each instance-manager pod utilizes 1 CPU core. This high CPU usage is attributed to the spdk_tgt process running within each instance-manager pod. The spdk_tgt process is responsible for handling input/output (IO) operations and requires intensive polling. As a result, it consumes 100% of a dedicated CPU core to efficiently manage and process the IO requests, ensuring optimal performance and responsiveness for storage operations." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: boolean + default: false +- variable: defaultSettings.v2DataEngineHugepageLimit + label: V2 Data Engine + description: "This allows users to configure maximum huge page size (in MiB) for the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: int + default: "2048" +- variable: defaultSettings.offlineReplicaRebuilding + label: Offline Replica Rebuilding + description: "Setting that allows rebuilding of offline replicas for volumes using the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + required: true + type: enum + options: + - "enabled" + - "disabled" + default: "enabled" +- variable: persistence.defaultClass + default: "true" + description: "Setting that allows you to specify the default Longhorn StorageClass." + label: Default Storage Class + group: "Longhorn Storage Class Settings" + required: true + type: boolean +- variable: persistence.reclaimPolicy + label: Storage Class Retain Policy + description: "Reclaim policy that provides instructions for handling of a volume after its claim is released. (Options: \"Retain\", \"Delete\")" + group: "Longhorn Storage Class Settings" + required: true + type: enum + options: + - "Delete" + - "Retain" + default: "Delete" +- variable: persistence.defaultClassReplicaCount + description: "Replica count of the default Longhorn StorageClass." + label: Default Storage Class Replica Count + group: "Longhorn Storage Class Settings" + type: int + min: 1 + max: 10 + default: 3 +- variable: persistence.defaultDataLocality + description: "Data locality of the default Longhorn StorageClass. (Options: \"disabled\", \"best-effort\")" + label: Default Storage Class Data Locality + group: "Longhorn Storage Class Settings" + type: enum + options: + - "disabled" + - "best-effort" + default: "disabled" +- variable: persistence.recurringJobSelector.enable + description: "Setting that allows you to enable the recurring job selector for a Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Recurring Job Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.recurringJobSelector.jobList + description: 'Recurring job selector for a Longhorn StorageClass. Ensure that quotes are used correctly when specifying job parameters. (Example: `[{"name":"backup", "isGroup":true}]`)' + label: Storage Class Recurring Job Selector List + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.defaultNodeSelector.enable + description: "Setting that allows you to enable the node selector for the default Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Node Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.defaultNodeSelector.selector + label: Storage Class Node Selector + description: 'Node selector for the default Longhorn StorageClass. Longhorn uses only nodes with the specified tags for storing volume data. (Examples: "storage,fast")' + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.backingImage.enable + description: "Setting that allows you to use a backing image in a Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Default Storage Class Backing Image + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.backingImage.name + description: 'Backing image to be used for creating and restoring volumes in a Longhorn StorageClass. When no backing images are available, specify the data source type and parameters that Longhorn can use to create a backing image.' + label: Storage Class Backing Image Name + group: "Longhorn Storage Class Settings" + type: string + default: + - variable: persistence.backingImage.expectedChecksum + description: 'Expected SHA-512 checksum of a backing image used in a Longhorn StorageClass. + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - It is not recommended to set this field if the data source type is \"export-from-volume\".' + label: Storage Class Backing Image Expected SHA512 Checksum + group: "Longhorn Storage Class Settings" + type: string + default: + - variable: persistence.backingImage.dataSourceType + description: 'Data source type of a backing image used in a Longhorn StorageClass. If the backing image exists in the cluster, Longhorn uses this setting to verify the image. If the backing image does not exist, Longhorn creates one using the specified data source type. + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - As for backing image creation with data source type \"upload\", it is recommended to do it via UI rather than StorageClass here. Uploading requires file data sending to the Longhorn backend after the object creation, which is complicated if you want to handle it manually.' + label: Storage Class Backing Image Data Source Type + group: "Longhorn Storage Class Settings" + type: enum + options: + - "" + - "download" + - "upload" + - "export-from-volume" + default: "" + - variable: persistence.backingImage.dataSourceParameters + description: "Data source parameters of a backing image used in a Longhorn StorageClass. You can specify a JSON string of a map. (Example: `'{\"url\":\"https://backing-image-example.s3-region.amazonaws.com/test-backing-image\"}'`) + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - Be careful of the quotes here." + label: Storage Class Backing Image Data Source Parameters + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.removeSnapshotsDuringFilesystemTrim + description: "Setting that allows you to enable automatic snapshot removal during filesystem trim for a Longhorn StorageClass. (Options: \"ignored\", \"enabled\", \"disabled\")" + label: Default Storage Class Remove Snapshots During Filesystem Trim + group: "Longhorn Storage Class Settings" + type: enum + options: + - "ignored" + - "enabled" + - "disabled" + default: "ignored" +- variable: ingress.enabled + default: "false" + description: "Expose app using Layer 7 Load Balancer - ingress" + type: boolean + group: "Services and Load Balancing" + label: Expose app using Layer 7 Load Balancer + show_subquestion_if: true + subquestions: + - variable: ingress.host + default: "xip.io" + description: "Hostname of the Layer 7 load balancer." + type: hostname + required: true + label: Layer 7 Load Balancer Hostname + - variable: ingress.path + default: "/" + description: "Default ingress path. You can access the Longhorn UI by following the full ingress path {{host}}+{{path}}." + type: string + required: true + label: Ingress Path +- variable: service.ui.type + default: "Rancher-Proxy" + description: "Service type for Longhorn UI. (Options: \"ClusterIP\", \"NodePort\", \"LoadBalancer\", \"Rancher-Proxy\")" + type: enum + options: + - "ClusterIP" + - "NodePort" + - "LoadBalancer" + - "Rancher-Proxy" + label: Longhorn UI Service + show_if: "ingress.enabled=false" + group: "Services and Load Balancing" + show_subquestion_if: "NodePort" + subquestions: + - variable: service.ui.nodePort + default: "" + description: "NodePort port number for Longhorn UI. When unspecified, Longhorn selects a free port between 30000 and 32767." + type: int + min: 30000 + max: 32767 + show_if: "service.ui.type=NodePort||service.ui.type=LoadBalancer" + label: UI Service NodePort number +- variable: enablePSP + default: "false" + description: "Setting that allows you to enable pod security policies (PSPs) that allow privileged Longhorn pods to start. This setting applies only to clusters running Kubernetes 1.25 and earlier, and with the built-in Pod Security admission controller enabled." + label: Pod Security Policy + type: boolean + group: "Other Settings" +- variable: global.cattle.windowsCluster.enabled + default: "false" + description: "Setting that allows Longhorn to run on a Rancher Windows cluster." + label: Rancher Windows Cluster + type: boolean + group: "Other Settings" +- variable: networkPolicies.enabled + description: "Setting that allows you to enable network policies that control access to Longhorn pods. + Warning: The Rancher Proxy will not work if this feature is enabled and a custom NetworkPolicy must be added." + group: "Other Settings" + label: Network Policies + default: "false" + type: boolean + subquestions: + - variable: networkPolicies.type + label: Network Policies for Ingress + description: "Distribution that determines the policy for allowing access for an ingress. (Options: \"k3s\", \"rke2\", \"rke1\")" + show_if: "networkPolicies.enabled=true&&ingress.enabled=true" + type: enum + default: "rke2" + options: + - "rke1" + - "rke2" + - "k3s" + - variable: defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU + label: Guaranteed Instance Manager CPU for V2 Data Engine + description: 'Number of millicpus on each node to be reserved for each Instance Manager pod when the V2 Data Engine is enabled. The default value is "1250". + WARNING: + - Specifying a value of 0 disables CPU requests for instance manager pods. You must specify an integer between 1000 and 8000. + - This is a global setting. Modifying the value triggers an automatic restart of the instance manager pods. Do not modify the value while volumes are still attached." + group: "Longhorn Default Settings' + type: int + min: 1000 + max: 8000 + default: 1250 \ No newline at end of file diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/NOTES.txt b/charts/longhorn/105.0.1+up1.6.4/templates/NOTES.txt new file mode 100644 index 0000000000..cca7cd77b9 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/NOTES.txt @@ -0,0 +1,5 @@ +Longhorn is now installed on the cluster! + +Please wait a few minutes for other Longhorn components such as CSI deployments, Engine Images, and Instance Managers to be initialized. + +Visit our documentation at https://longhorn.io/docs/ diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/_helpers.tpl b/charts/longhorn/105.0.1+up1.6.4/templates/_helpers.tpl new file mode 100644 index 0000000000..3fbc2ac02f --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/_helpers.tpl @@ -0,0 +1,66 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "longhorn.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +*/}} +{{- define "longhorn.fullname" -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "longhorn.managerIP" -}} +{{- $fullname := (include "longhorn.fullname" .) -}} +{{- printf "http://%s-backend:9500" $fullname | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "secret" }} +{{- printf "{\"auths\": {\"%s\": {\"auth\": \"%s\"}}}" .Values.privateRegistry.registryUrl (printf "%s:%s" .Values.privateRegistry.registryUser .Values.privateRegistry.registryPasswd | b64enc) | b64enc }} +{{- end }} + +{{- /* +longhorn.labels generates the standard Helm labels. +*/ -}} +{{- define "longhorn.labels" -}} +app.kubernetes.io/name: {{ template "longhorn.name" . }} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +app.kubernetes.io/instance: {{ .Release.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +{{- end -}} + + +{{- define "system_default_registry" -}} +{{- if .Values.global.cattle.systemDefaultRegistry -}} +{{- printf "%s/" .Values.global.cattle.systemDefaultRegistry -}} +{{- else -}} +{{- "" -}} +{{- end -}} +{{- end -}} + +{{- define "registry_url" -}} +{{- if .Values.privateRegistry.registryUrl -}} +{{- printf "%s/" .Values.privateRegistry.registryUrl -}} +{{- else -}} +{{ include "system_default_registry" . }} +{{- end -}} +{{- end -}} + +{{- /* + define the longhorn release namespace +*/ -}} +{{- define "release_namespace" -}} +{{- if .Values.namespaceOverride -}} +{{- .Values.namespaceOverride -}} +{{- else -}} +{{- .Release.Namespace -}} +{{- end -}} +{{- end -}} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/clusterrole.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/clusterrole.yaml new file mode 100644 index 0000000000..f6e069f004 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/clusterrole.yaml @@ -0,0 +1,77 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: longhorn-role + labels: {{- include "longhorn.labels" . | nindent 4 }} +rules: +- apiGroups: + - apiextensions.k8s.io + resources: + - customresourcedefinitions + verbs: + - "*" +- apiGroups: [""] + resources: ["pods", "events", "persistentvolumes", "persistentvolumeclaims","persistentvolumeclaims/status", "nodes", "proxy/nodes", "pods/log", "secrets", "services", "endpoints", "configmaps", "serviceaccounts"] + verbs: ["*"] +- apiGroups: [""] + resources: ["namespaces"] + verbs: ["get", "list"] +- apiGroups: ["apps"] + resources: ["daemonsets", "statefulsets", "deployments"] + verbs: ["*"] +- apiGroups: ["batch"] + resources: ["jobs", "cronjobs"] + verbs: ["*"] +- apiGroups: ["policy"] + resources: ["poddisruptionbudgets", "podsecuritypolicies"] + verbs: ["*"] +- apiGroups: ["scheduling.k8s.io"] + resources: ["priorityclasses"] + verbs: ["watch", "list"] +- apiGroups: ["storage.k8s.io"] + resources: ["storageclasses", "volumeattachments", "volumeattachments/status", "csinodes", "csidrivers"] + verbs: ["*"] +- apiGroups: ["snapshot.storage.k8s.io"] + resources: ["volumesnapshotclasses", "volumesnapshots", "volumesnapshotcontents", "volumesnapshotcontents/status"] + verbs: ["*"] +- apiGroups: ["longhorn.io"] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + {{- if .Values.openshift.enabled }} + "engineimages/finalizers", "nodes/finalizers", "instancemanagers/finalizers", + {{- end }} + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status", "backupbackingimages", "backupbackingimages/status"] + verbs: ["*"] +- apiGroups: ["coordination.k8s.io"] + resources: ["leases"] + verbs: ["*"] +- apiGroups: ["metrics.k8s.io"] + resources: ["pods", "nodes"] + verbs: ["get", "list"] +- apiGroups: ["apiregistration.k8s.io"] + resources: ["apiservices"] + verbs: ["list", "watch"] +- apiGroups: ["admissionregistration.k8s.io"] + resources: ["mutatingwebhookconfigurations", "validatingwebhookconfigurations"] + verbs: ["get", "list", "create", "patch", "delete"] +- apiGroups: ["rbac.authorization.k8s.io"] + resources: ["roles", "rolebindings", "clusterrolebindings", "clusterroles"] + verbs: ["*"] +{{- if .Values.openshift.enabled }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: longhorn-ocp-privileged-role + labels: {{- include "longhorn.labels" . | nindent 4 }} +rules: +- apiGroups: ["security.openshift.io"] + resources: ["securitycontextconstraints"] + resourceNames: ["anyuid", "privileged"] + verbs: ["use"] +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/clusterrolebinding.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/clusterrolebinding.yaml new file mode 100644 index 0000000000..2e34f014ce --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/clusterrolebinding.yaml @@ -0,0 +1,49 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-bind + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: longhorn-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-support-bundle + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: +- kind: ServiceAccount + name: longhorn-support-bundle + namespace: {{ include "release_namespace" . }} +{{- if .Values.openshift.enabled }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-ocp-privileged-bind + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: longhorn-ocp-privileged-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: longhorn-ui-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: default # supportbundle-agent-support-bundle uses default sa + namespace: {{ include "release_namespace" . }} +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/daemonset-sa.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/daemonset-sa.yaml new file mode 100644 index 0000000000..bbcd59fd1e --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/daemonset-sa.yaml @@ -0,0 +1,167 @@ +apiVersion: apps/v1 +kind: DaemonSet +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-manager + name: longhorn-manager + namespace: {{ include "release_namespace" . }} +spec: + selector: + matchLabels: + app: longhorn-manager + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-manager + {{- with .Values.annotations }} + annotations: + {{- toYaml . | nindent 8 }} + {{- end }} + spec: + containers: + - name: longhorn-manager + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + privileged: true + command: + - longhorn-manager + - -d + {{- if eq .Values.longhornManager.log.format "json" }} + - -j + {{- end }} + - daemon + - --engine-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.engine.repository }}:{{ .Values.image.longhorn.engine.tag }}" + - --instance-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.instanceManager.repository }}:{{ .Values.image.longhorn.instanceManager.tag }}" + - --share-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.shareManager.repository }}:{{ .Values.image.longhorn.shareManager.tag }}" + - --backing-image-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.backingImageManager.repository }}:{{ .Values.image.longhorn.backingImageManager.tag }}" + - --support-bundle-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.supportBundleKit.repository }}:{{ .Values.image.longhorn.supportBundleKit.tag }}" + - --manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }}" + - --service-account + - longhorn-service-account + {{- if .Values.preUpgradeChecker.upgradeVersionCheck}} + - --upgrade-version-check + {{- end }} + ports: + - containerPort: 9500 + name: manager + - containerPort: 9501 + name: conversion-wh + - containerPort: 9502 + name: admission-wh + - containerPort: 9503 + name: recov-backend + readinessProbe: + httpGet: + path: /v1/healthz + port: 9501 + scheme: HTTPS + volumeMounts: + - name: dev + mountPath: /host/dev/ + - name: proc + mountPath: /host/proc/ + - name: longhorn + mountPath: /var/lib/longhorn/ + mountPropagation: Bidirectional + - name: longhorn-grpc-tls + mountPath: /tls-files/ + {{- if .Values.enableGoCoverDir }} + - name: go-cover-dir + mountPath: /go-cover-dir/ + {{- end }} + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: POD_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + {{- if .Values.enableGoCoverDir }} + - name: GOCOVERDIR + value: /go-cover-dir/ + {{- end }} + volumes: + - name: dev + hostPath: + path: /dev/ + - name: proc + hostPath: + path: /proc/ + - name: longhorn + hostPath: + path: /var/lib/longhorn/ + {{- if .Values.enableGoCoverDir }} + - name: go-cover-dir + hostPath: + path: /go-cover-dir/ + type: DirectoryOrCreate + {{- end }} + - name: longhorn-grpc-tls + secret: + secretName: longhorn-grpc-tls + optional: true + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} + serviceAccountName: longhorn-service-account + updateStrategy: + rollingUpdate: + maxUnavailable: "100%" +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-manager + name: longhorn-backend + namespace: {{ include "release_namespace" . }} + {{- if .Values.longhornManager.serviceAnnotations }} + annotations: +{{ toYaml .Values.longhornManager.serviceAnnotations | indent 4 }} + {{- end }} +spec: + type: {{ .Values.service.manager.type }} + selector: + app: longhorn-manager + ports: + - name: manager + port: 9500 + targetPort: manager + {{- if .Values.service.manager.nodePort }} + nodePort: {{ .Values.service.manager.nodePort }} + {{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/default-setting.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/default-setting.yaml new file mode 100644 index 0000000000..5261f7fef8 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/default-setting.yaml @@ -0,0 +1,229 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-default-setting + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +data: + default-setting.yaml: |- + {{- if not (kindIs "invalid" .Values.defaultSettings.backupTarget) }} + backup-target: {{ .Values.defaultSettings.backupTarget }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupTargetCredentialSecret) }} + backup-target-credential-secret: {{ .Values.defaultSettings.backupTargetCredentialSecret }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowRecurringJobWhileVolumeDetached) }} + allow-recurring-job-while-volume-detached: {{ .Values.defaultSettings.allowRecurringJobWhileVolumeDetached }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.createDefaultDiskLabeledNodes) }} + create-default-disk-labeled-nodes: {{ .Values.defaultSettings.createDefaultDiskLabeledNodes }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultDataPath) }} + default-data-path: {{ .Values.defaultSettings.defaultDataPath }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaSoftAntiAffinity) }} + replica-soft-anti-affinity: {{ .Values.defaultSettings.replicaSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaAutoBalance) }} + replica-auto-balance: {{ .Values.defaultSettings.replicaAutoBalance }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageOverProvisioningPercentage) }} + storage-over-provisioning-percentage: {{ .Values.defaultSettings.storageOverProvisioningPercentage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageMinimalAvailablePercentage) }} + storage-minimal-available-percentage: {{ .Values.defaultSettings.storageMinimalAvailablePercentage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageReservedPercentageForDefaultDisk) }} + storage-reserved-percentage-for-default-disk: {{ .Values.defaultSettings.storageReservedPercentageForDefaultDisk }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.upgradeChecker) }} + upgrade-checker: {{ .Values.defaultSettings.upgradeChecker }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultReplicaCount) }} + default-replica-count: {{ .Values.defaultSettings.defaultReplicaCount }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultDataLocality) }} + default-data-locality: {{ .Values.defaultSettings.defaultDataLocality }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultLonghornStaticStorageClass) }} + default-longhorn-static-storage-class: {{ .Values.defaultSettings.defaultLonghornStaticStorageClass }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupstorePollInterval) }} + backupstore-poll-interval: {{ .Values.defaultSettings.backupstorePollInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.failedBackupTTL) }} + failed-backup-ttl: {{ .Values.defaultSettings.failedBackupTTL }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.restoreVolumeRecurringJobs) }} + restore-volume-recurring-jobs: {{ .Values.defaultSettings.restoreVolumeRecurringJobs }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringSuccessfulJobsHistoryLimit) }} + recurring-successful-jobs-history-limit: {{ .Values.defaultSettings.recurringSuccessfulJobsHistoryLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringJobMaxRetention) }} + recurring-job-max-retention: {{ .Values.defaultSettings.recurringJobMaxRetention }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringFailedJobsHistoryLimit) }} + recurring-failed-jobs-history-limit: {{ .Values.defaultSettings.recurringFailedJobsHistoryLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.supportBundleFailedHistoryLimit) }} + support-bundle-failed-history-limit: {{ .Values.defaultSettings.supportBundleFailedHistoryLimit }} + {{- end }} + {{- if or (not (kindIs "invalid" .Values.defaultSettings.taintToleration)) (.Values.global.cattle.windowsCluster.enabled) }} + taint-toleration: {{ $windowsDefaultSettingTaintToleration := list }}{{ $defaultSettingTaintToleration := list -}} + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.defaultSetting.taintToleration -}} + {{- $windowsDefaultSettingTaintToleration = .Values.global.cattle.windowsCluster.defaultSetting.taintToleration -}} + {{- end -}} + {{- if not (kindIs "invalid" .Values.defaultSettings.taintToleration) -}} + {{- $defaultSettingTaintToleration = .Values.defaultSettings.taintToleration -}} + {{- end -}} + {{- $taintToleration := list $windowsDefaultSettingTaintToleration $defaultSettingTaintToleration }}{{ join ";" (compact $taintToleration) -}} + {{- end }} + {{- if or (not (kindIs "invalid" .Values.defaultSettings.systemManagedComponentsNodeSelector)) (.Values.global.cattle.windowsCluster.enabled) }} + system-managed-components-node-selector: {{ $windowsDefaultSettingNodeSelector := list }}{{ $defaultSettingNodeSelector := list -}} + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.defaultSetting.systemManagedComponentsNodeSelector -}} + {{ $windowsDefaultSettingNodeSelector = .Values.global.cattle.windowsCluster.defaultSetting.systemManagedComponentsNodeSelector -}} + {{- end -}} + {{- if not (kindIs "invalid" .Values.defaultSettings.systemManagedComponentsNodeSelector) -}} + {{- $defaultSettingNodeSelector = .Values.defaultSettings.systemManagedComponentsNodeSelector -}} + {{- end -}} + {{- $nodeSelector := list $windowsDefaultSettingNodeSelector $defaultSettingNodeSelector }}{{ join ";" (compact $nodeSelector) -}} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.priorityClass) }} + priority-class: {{ .Values.defaultSettings.priorityClass }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoSalvage) }} + auto-salvage: {{ .Values.defaultSettings.autoSalvage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly) }} + auto-delete-pod-when-volume-detached-unexpectedly: {{ .Values.defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableSchedulingOnCordonedNode) }} + disable-scheduling-on-cordoned-node: {{ .Values.defaultSettings.disableSchedulingOnCordonedNode }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaZoneSoftAntiAffinity) }} + replica-zone-soft-anti-affinity: {{ .Values.defaultSettings.replicaZoneSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaDiskSoftAntiAffinity) }} + replica-disk-soft-anti-affinity: {{ .Values.defaultSettings.replicaDiskSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.nodeDownPodDeletionPolicy) }} + node-down-pod-deletion-policy: {{ .Values.defaultSettings.nodeDownPodDeletionPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.nodeDrainPolicy) }} + node-drain-policy: {{ .Values.defaultSettings.nodeDrainPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.detachManuallyAttachedVolumesWhenCordoned) }} + detach-manually-attached-volumes-when-cordoned: {{ .Values.defaultSettings.detachManuallyAttachedVolumesWhenCordoned }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaReplenishmentWaitInterval) }} + replica-replenishment-wait-interval: {{ .Values.defaultSettings.replicaReplenishmentWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentReplicaRebuildPerNodeLimit) }} + concurrent-replica-rebuild-per-node-limit: {{ .Values.defaultSettings.concurrentReplicaRebuildPerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentVolumeBackupRestorePerNodeLimit) }} + concurrent-volume-backup-restore-per-node-limit: {{ .Values.defaultSettings.concurrentVolumeBackupRestorePerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableRevisionCounter) }} + disable-revision-counter: {{ .Values.defaultSettings.disableRevisionCounter }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.systemManagedPodsImagePullPolicy) }} + system-managed-pods-image-pull-policy: {{ .Values.defaultSettings.systemManagedPodsImagePullPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowVolumeCreationWithDegradedAvailability) }} + allow-volume-creation-with-degraded-availability: {{ .Values.defaultSettings.allowVolumeCreationWithDegradedAvailability }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupSystemGeneratedSnapshot) }} + auto-cleanup-system-generated-snapshot: {{ .Values.defaultSettings.autoCleanupSystemGeneratedSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupRecurringJobBackupSnapshot) }} + auto-cleanup-recurring-job-backup-snapshot: {{ .Values.defaultSettings.autoCleanupRecurringJobBackupSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit) }} + concurrent-automatic-engine-upgrade-per-node-limit: {{ .Values.defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backingImageCleanupWaitInterval) }} + backing-image-cleanup-wait-interval: {{ .Values.defaultSettings.backingImageCleanupWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backingImageRecoveryWaitInterval) }} + backing-image-recovery-wait-interval: {{ .Values.defaultSettings.backingImageRecoveryWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.guaranteedInstanceManagerCPU) }} + guaranteed-instance-manager-cpu: {{ .Values.defaultSettings.guaranteedInstanceManagerCPU }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.kubernetesClusterAutoscalerEnabled) }} + kubernetes-cluster-autoscaler-enabled: {{ .Values.defaultSettings.kubernetesClusterAutoscalerEnabled }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.orphanAutoDeletion) }} + orphan-auto-deletion: {{ .Values.defaultSettings.orphanAutoDeletion }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageNetwork) }} + storage-network: {{ .Values.defaultSettings.storageNetwork }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.deletingConfirmationFlag) }} + deleting-confirmation-flag: {{ .Values.defaultSettings.deletingConfirmationFlag }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.engineReplicaTimeout) }} + engine-replica-timeout: {{ .Values.defaultSettings.engineReplicaTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrity) }} + snapshot-data-integrity: {{ .Values.defaultSettings.snapshotDataIntegrity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation) }} + snapshot-data-integrity-immediate-check-after-snapshot-creation: {{ .Values.defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrityCronjob) }} + snapshot-data-integrity-cronjob: {{ .Values.defaultSettings.snapshotDataIntegrityCronjob }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.removeSnapshotsDuringFilesystemTrim) }} + remove-snapshots-during-filesystem-trim: {{ .Values.defaultSettings.removeSnapshotsDuringFilesystemTrim }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.fastReplicaRebuildEnabled) }} + fast-replica-rebuild-enabled: {{ .Values.defaultSettings.fastReplicaRebuildEnabled }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaFileSyncHttpClientTimeout) }} + replica-file-sync-http-client-timeout: {{ .Values.defaultSettings.replicaFileSyncHttpClientTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.logLevel) }} + log-level: {{ .Values.defaultSettings.logLevel }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupCompressionMethod) }} + backup-compression-method: {{ .Values.defaultSettings.backupCompressionMethod }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupConcurrentLimit) }} + backup-concurrent-limit: {{ .Values.defaultSettings.backupConcurrentLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.restoreConcurrentLimit) }} + restore-concurrent-limit: {{ .Values.defaultSettings.restoreConcurrentLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v1DataEngine) }} + v1-data-engine: {{ .Values.defaultSettings.v1DataEngine }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngine) }} + v2-data-engine: {{ .Values.defaultSettings.v2DataEngine }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineHugepageLimit) }} + v2-data-engine-hugepage-limit: {{ .Values.defaultSettings.v2DataEngineHugepageLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.offlineReplicaRebuilding) }} + offline-replica-rebuilding: {{ .Values.defaultSettings.offlineReplicaRebuilding }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowEmptyNodeSelectorVolume) }} + allow-empty-node-selector-volume: {{ .Values.defaultSettings.allowEmptyNodeSelectorVolume }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowEmptyDiskSelectorVolume) }} + allow-empty-disk-selector-volume: {{ .Values.defaultSettings.allowEmptyDiskSelectorVolume }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowCollectingLonghornUsageMetrics) }} + allow-collecting-longhorn-usage-metrics: {{ .Values.defaultSettings.allowCollectingLonghornUsageMetrics }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableSnapshotPurge) }} + disable-snapshot-purge: {{ .Values.defaultSettings.disableSnapshotPurge }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU) }} + v2-data-engine-guaranteed-instance-manager-cpu: {{ .Values.defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotMaxCount) }} + snapshot-max-count: {{ .Values.defaultSettings.snapshotMaxCount }} + {{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/deployment-driver.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/deployment-driver.yaml new file mode 100644 index 0000000000..5683c759e7 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/deployment-driver.yaml @@ -0,0 +1,135 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: longhorn-driver-deployer + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + replicas: 1 + selector: + matchLabels: + app: longhorn-driver-deployer + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-driver-deployer + spec: + initContainers: + - name: wait-longhorn-manager + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + command: ['sh', '-c', 'while [ $(curl -m 1 -s -o /dev/null -w "%{http_code}" http://longhorn-backend:9500/v1) != "200" ]; do echo waiting; sleep 2; done'] + containers: + - name: longhorn-driver-deployer + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - -d + {{- if eq .Values.longhornDriver.log.format "json" }} + - -j + {{- end }} + - deploy-driver + - --manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }}" + - --manager-url + - http://longhorn-backend:9500/v1 + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + - name: SERVICE_ACCOUNT + valueFrom: + fieldRef: + fieldPath: spec.serviceAccountName + {{- if .Values.csi.kubeletRootDir }} + - name: KUBELET_ROOT_DIR + value: {{ .Values.csi.kubeletRootDir }} + {{- end }} + {{- if and .Values.image.csi.attacher.repository .Values.image.csi.attacher.tag }} + - name: CSI_ATTACHER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.attacher.repository }}:{{ .Values.image.csi.attacher.tag }}" + {{- end }} + {{- if and .Values.image.csi.provisioner.repository .Values.image.csi.provisioner.tag }} + - name: CSI_PROVISIONER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.provisioner.repository }}:{{ .Values.image.csi.provisioner.tag }}" + {{- end }} + {{- if and .Values.image.csi.nodeDriverRegistrar.repository .Values.image.csi.nodeDriverRegistrar.tag }} + - name: CSI_NODE_DRIVER_REGISTRAR_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.nodeDriverRegistrar.repository }}:{{ .Values.image.csi.nodeDriverRegistrar.tag }}" + {{- end }} + {{- if and .Values.image.csi.resizer.repository .Values.image.csi.resizer.tag }} + - name: CSI_RESIZER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.resizer.repository }}:{{ .Values.image.csi.resizer.tag }}" + {{- end }} + {{- if and .Values.image.csi.snapshotter.repository .Values.image.csi.snapshotter.tag }} + - name: CSI_SNAPSHOTTER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.snapshotter.repository }}:{{ .Values.image.csi.snapshotter.tag }}" + {{- end }} + {{- if and .Values.image.csi.livenessProbe.repository .Values.image.csi.livenessProbe.tag }} + - name: CSI_LIVENESS_PROBE_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.livenessProbe.repository }}:{{ .Values.image.csi.livenessProbe.tag }}" + {{- end }} + {{- if .Values.csi.attacherReplicaCount }} + - name: CSI_ATTACHER_REPLICA_COUNT + value: {{ .Values.csi.attacherReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.provisionerReplicaCount }} + - name: CSI_PROVISIONER_REPLICA_COUNT + value: {{ .Values.csi.provisionerReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.resizerReplicaCount }} + - name: CSI_RESIZER_REPLICA_COUNT + value: {{ .Values.csi.resizerReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.snapshotterReplicaCount }} + - name: CSI_SNAPSHOTTER_REPLICA_COUNT + value: {{ .Values.csi.snapshotterReplicaCount | quote }} + {{- end }} + {{- if .Values.enableGoCoverDir }} + - name: GOCOVERDIR + value: /go-cover-dir/ + volumeMounts: + - name: go-cover-dir + mountPath: /go-cover-dir/ + {{- end }} + + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornDriver.priorityClass }} + priorityClassName: {{ .Values.longhornDriver.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornDriver.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornDriver.tolerations }} +{{ default .Values.global.tolerations .Values.longhornDriver.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornDriver.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornDriver.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornDriver.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} + serviceAccountName: longhorn-service-account + securityContext: + runAsUser: 0 + {{- if .Values.enableGoCoverDir }} + volumes: + - name: go-cover-dir + hostPath: + path: /go-cover-dir/ + type: DirectoryOrCreate + {{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/deployment-ui.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/deployment-ui.yaml new file mode 100644 index 0000000000..e4f3e0f8f7 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/deployment-ui.yaml @@ -0,0 +1,186 @@ +{{- if .Values.openshift.enabled }} +{{- if .Values.openshift.ui.route }} +# https://github.com/openshift/oauth-proxy/blob/master/contrib/sidecar.yaml +# Create a proxy service account and ensure it will use the route "proxy" +# Create a secure connection to the proxy via a route +apiVersion: route.openshift.io/v1 +kind: Route +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: {{ .Values.openshift.ui.route }} + namespace: {{ include "release_namespace" . }} +spec: + to: + kind: Service + name: longhorn-ui + tls: + termination: reencrypt +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: longhorn-ui + namespace: {{ include "release_namespace" . }} + annotations: + service.alpha.openshift.io/serving-cert-secret-name: longhorn-ui-tls +spec: + ports: + - name: longhorn-ui + port: {{ .Values.openshift.ui.port | default 443 }} + targetPort: {{ .Values.openshift.ui.proxy | default 8443 }} + selector: + app: longhorn-ui +--- +{{- end }} +{{- end }} +apiVersion: apps/v1 +kind: Deployment +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: longhorn-ui + namespace: {{ include "release_namespace" . }} +spec: + replicas: {{ .Values.longhornUI.replicas }} + selector: + matchLabels: + app: longhorn-ui + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-ui + spec: + serviceAccountName: longhorn-ui-service-account + affinity: + podAntiAffinity: + preferredDuringSchedulingIgnoredDuringExecution: + - weight: 1 + podAffinityTerm: + labelSelector: + matchExpressions: + - key: app + operator: In + values: + - longhorn-ui + topologyKey: kubernetes.io/hostname + containers: + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + - name: oauth-proxy + {{- if .Values.image.openshift.oauthProxy.repository }} + image: {{ template "registry_url" . }}{{ .Values.image.openshift.oauthProxy.repository }}:{{ .Values.image.openshift.oauthProxy.tag }} + {{- else }} + image: "" + {{- end }} + imagePullPolicy: IfNotPresent + ports: + - containerPort: {{ .Values.openshift.ui.proxy | default 8443 }} + name: public + args: + - --https-address=:{{ .Values.openshift.ui.proxy | default 8443 }} + - --provider=openshift + - --openshift-service-account=longhorn-ui-service-account + - --upstream=http://localhost:8000 + - --tls-cert=/etc/tls/private/tls.crt + - --tls-key=/etc/tls/private/tls.key + - --cookie-secret=SECRET + - --openshift-sar={"namespace":"{{ include "release_namespace" . }}","group":"longhorn.io","resource":"setting","verb":"delete"} + volumeMounts: + - mountPath: /etc/tls/private + name: longhorn-ui-tls + {{- end }} + {{- end }} + - name: longhorn-ui + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.ui.repository }}:{{ .Values.image.longhorn.ui.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + volumeMounts: + - name : nginx-cache + mountPath: /var/cache/nginx/ + - name : nginx-config + mountPath: /var/config/nginx/ + - name: var-run + mountPath: /var/run/ + ports: + - containerPort: 8000 + name: http + env: + - name: LONGHORN_MANAGER_IP + value: "http://longhorn-backend:9500" + - name: LONGHORN_UI_PORT + value: "8000" + volumes: + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + - name: longhorn-ui-tls + secret: + secretName: longhorn-ui-tls + {{- end }} + {{- end }} + - emptyDir: {} + name: nginx-cache + - emptyDir: {} + name: nginx-config + - emptyDir: {} + name: var-run + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornUI.priorityClass }} + priorityClassName: {{ .Values.longhornUI.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornUI.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornUI.tolerations }} +{{ default .Values.global.tolerations .Values.longhornUI.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornUI.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornUI.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornUI.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} +--- +kind: Service +apiVersion: v1 +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + {{- if eq .Values.service.ui.type "Rancher-Proxy" }} + kubernetes.io/cluster-service: "true" + {{- end }} + name: longhorn-frontend + namespace: {{ include "release_namespace" . }} +spec: + {{- if eq .Values.service.ui.type "Rancher-Proxy" }} + type: ClusterIP + {{- else }} + type: {{ .Values.service.ui.type }} + {{- end }} + {{- if and .Values.service.ui.loadBalancerIP (eq .Values.service.ui.type "LoadBalancer") }} + loadBalancerIP: {{ .Values.service.ui.loadBalancerIP }} + {{- end }} + {{- if and (eq .Values.service.ui.type "LoadBalancer") .Values.service.ui.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.service.ui.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + selector: + app: longhorn-ui + ports: + - name: http + port: 80 + targetPort: http + {{- if .Values.service.ui.nodePort }} + nodePort: {{ .Values.service.ui.nodePort }} + {{- else }} + nodePort: null + {{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/ingress.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/ingress.yaml new file mode 100644 index 0000000000..9038ff0cc1 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/ingress.yaml @@ -0,0 +1,37 @@ +{{- if .Values.ingress.enabled }} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: longhorn-ingress + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ingress + annotations: + {{- if .Values.ingress.secureBackends }} + ingress.kubernetes.io/secure-backends: "true" + {{- end }} + {{- range $key, $value := .Values.ingress.annotations }} + {{ $key }}: {{ $value | quote }} + {{- end }} +spec: + {{- if .Values.ingress.ingressClassName }} + ingressClassName: {{ .Values.ingress.ingressClassName }} + {{- end }} + rules: + - host: {{ .Values.ingress.host }} + http: + paths: + - path: {{ default "" .Values.ingress.path }} + pathType: ImplementationSpecific + backend: + service: + name: longhorn-frontend + port: + number: 80 +{{- if .Values.ingress.tls }} + tls: + - hosts: + - {{ .Values.ingress.host }} + secretName: {{ .Values.ingress.tlsSecret }} +{{- end }} +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/backing-image-data-source-network-policy.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/backing-image-data-source-network-policy.yaml new file mode 100644 index 0000000000..7204d63caa --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/backing-image-data-source-network-policy.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: backing-image-data-source + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/backing-image-manager-network-policy.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/backing-image-manager-network-policy.yaml new file mode 100644 index 0000000000..119ebf08a1 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/backing-image-manager-network-policy.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: backing-image-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/instance-manager-networking.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/instance-manager-networking.yaml new file mode 100644 index 0000000000..332aa2c2fe --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/instance-manager-networking.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: instance-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: instance-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/manager-network-policy.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/manager-network-policy.yaml new file mode 100644 index 0000000000..6f94029a53 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/manager-network-policy.yaml @@ -0,0 +1,35 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + app: longhorn-ui + - podSelector: + matchLabels: + app: longhorn-csi-plugin + - podSelector: + matchLabels: + longhorn.io/managed-by: longhorn-manager + matchExpressions: + - { key: recurring-job.longhorn.io, operator: Exists } + - podSelector: + matchExpressions: + - { key: longhorn.io/job-task, operator: Exists } + - podSelector: + matchLabels: + app: longhorn-driver-deployer +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/recovery-backend-network-policy.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/recovery-backend-network-policy.yaml new file mode 100644 index 0000000000..6e34dadfc2 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/recovery-backend-network-policy.yaml @@ -0,0 +1,17 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-recovery-backend + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9503 +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/ui-frontend-network-policy.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/ui-frontend-network-policy.yaml new file mode 100644 index 0000000000..6f37065980 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/ui-frontend-network-policy.yaml @@ -0,0 +1,46 @@ +{{- if and .Values.networkPolicies.enabled .Values.ingress.enabled (not (eq .Values.networkPolicies.type "")) }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-ui-frontend + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-ui + policyTypes: + - Ingress + ingress: + - from: + {{- if eq .Values.networkPolicies.type "rke1"}} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress-nginx + podSelector: + matchLabels: + app.kubernetes.io/component: controller + app.kubernetes.io/instance: ingress-nginx + app.kubernetes.io/name: ingress-nginx + {{- else if eq .Values.networkPolicies.type "rke2" }} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + podSelector: + matchLabels: + app.kubernetes.io/component: controller + app.kubernetes.io/instance: rke2-ingress-nginx + app.kubernetes.io/name: rke2-ingress-nginx + {{- else if eq .Values.networkPolicies.type "k3s" }} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + podSelector: + matchLabels: + app.kubernetes.io/name: traefik + ports: + - port: 8000 + protocol: TCP + - port: 80 + protocol: TCP + {{- end }} +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/webhook-network-policy.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/webhook-network-policy.yaml new file mode 100644 index 0000000000..3575763d39 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/network-policies/webhook-network-policy.yaml @@ -0,0 +1,33 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9501 +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-admission-webhook + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9502 +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/postupgrade-job.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/postupgrade-job.yaml new file mode 100644 index 0000000000..56efd38e9b --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/postupgrade-job.yaml @@ -0,0 +1,56 @@ +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": post-upgrade + "helm.sh/hook-delete-policy": hook-succeeded,before-hook-creation + name: longhorn-post-upgrade + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-post-upgrade + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-post-upgrade + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - post-upgrade + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: OnFailure + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/preupgrade-job.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/preupgrade-job.yaml new file mode 100644 index 0000000000..2b8333d89e --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/preupgrade-job.yaml @@ -0,0 +1,55 @@ +{{- if and .Values.preUpgradeChecker.jobEnabled .Values.preUpgradeChecker.upgradeVersionCheck}} +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": pre-upgrade + "helm.sh/hook-delete-policy": hook-succeeded,before-hook-creation,hook-failed + name: longhorn-pre-upgrade + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-pre-upgrade + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-pre-upgrade + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - pre-upgrade + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: OnFailure + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/priorityclass.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/priorityclass.yaml new file mode 100644 index 0000000000..208adc84a2 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/priorityclass.yaml @@ -0,0 +1,9 @@ +apiVersion: scheduling.k8s.io/v1 +kind: PriorityClass +metadata: + name: "longhorn-critical" + labels: {{- include "longhorn.labels" . | nindent 4 }} +description: "Ensure Longhorn pods have the highest priority to prevent any unexpected eviction by the Kubernetes scheduler under node pressure" +globalDefault: false +preemptionPolicy: PreemptLowerPriority +value: 1000000000 diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/psp.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/psp.yaml new file mode 100644 index 0000000000..a2dfc05bef --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/psp.yaml @@ -0,0 +1,66 @@ +{{- if .Values.enablePSP }} +apiVersion: policy/v1beta1 +kind: PodSecurityPolicy +metadata: + name: longhorn-psp + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + privileged: true + allowPrivilegeEscalation: true + requiredDropCapabilities: + - NET_RAW + allowedCapabilities: + - SYS_ADMIN + hostNetwork: false + hostIPC: false + hostPID: true + runAsUser: + rule: RunAsAny + seLinux: + rule: RunAsAny + fsGroup: + rule: RunAsAny + supplementalGroups: + rule: RunAsAny + volumes: + - configMap + - downwardAPI + - emptyDir + - secret + - projected + - hostPath +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: longhorn-psp-role + labels: {{- include "longhorn.labels" . | nindent 4 }} + namespace: {{ include "release_namespace" . }} +rules: +- apiGroups: + - policy + resources: + - podsecuritypolicies + verbs: + - use + resourceNames: + - longhorn-psp +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: longhorn-psp-binding + labels: {{- include "longhorn.labels" . | nindent 4 }} + namespace: {{ include "release_namespace" . }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: longhorn-psp-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: default + namespace: {{ include "release_namespace" . }} +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/registry-secret.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/registry-secret.yaml new file mode 100644 index 0000000000..3c6b1dc510 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/registry-secret.yaml @@ -0,0 +1,13 @@ +{{- if .Values.privateRegistry.createSecret }} +{{- if .Values.privateRegistry.registrySecret }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .Values.privateRegistry.registrySecret }} + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +type: kubernetes.io/dockerconfigjson +data: + .dockerconfigjson: {{ template "secret" . }} +{{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/serviceaccount.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/serviceaccount.yaml new file mode 100644 index 0000000000..b0d6dd505b --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/serviceaccount.yaml @@ -0,0 +1,40 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-ui-service-account + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + {{- if not .Values.serviceAccount.annotations }} + annotations: + {{- end }} + serviceaccounts.openshift.io/oauth-redirectreference.primary: '{"kind":"OAuthRedirectReference","apiVersion":"v1","reference":{"kind":"Route","name":"longhorn-ui"}}' + {{- end }} + {{- end }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-support-bundle + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/servicemonitor.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/servicemonitor.yaml new file mode 100644 index 0000000000..3f32961332 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/servicemonitor.yaml @@ -0,0 +1,40 @@ +{{- if .Values.metrics.serviceMonitor.enabled -}} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: longhorn-prometheus-servicemonitor + namespace: {{ include "release_namespace" . }} + labels: + {{- include "longhorn.labels" . | nindent 4 }} + name: longhorn-prometheus-servicemonitor + {{- with .Values.metrics.serviceMonitor.additionalLabels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: + app: longhorn-manager + namespaceSelector: + matchNames: + - {{ include "release_namespace" . }} + endpoints: + - port: manager + {{- with .Values.metrics.serviceMonitor.interval }} + interval: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.relabelings }} + relabelings: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.metricRelabelings }} + metricRelabelings: + {{- toYaml . | nindent 8 }} + {{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/services.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/services.yaml new file mode 100644 index 0000000000..9523cabcab --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/services.yaml @@ -0,0 +1,47 @@ +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-conversion-webhook + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + app: longhorn-manager + ports: + - name: conversion-webhook + port: 9501 + targetPort: conversion-wh +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-admission-webhook + name: longhorn-admission-webhook + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + app: longhorn-manager + ports: + - name: admission-webhook + port: 9502 + targetPort: admission-wh +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-recovery-backend + name: longhorn-recovery-backend + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + app: longhorn-manager + ports: + - name: recovery-backend + port: 9503 + targetPort: recov-backend diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/storageclass.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/storageclass.yaml new file mode 100644 index 0000000000..f79699f5e0 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/storageclass.yaml @@ -0,0 +1,50 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-storageclass + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +data: + storageclass.yaml: | + kind: StorageClass + apiVersion: storage.k8s.io/v1 + metadata: + name: longhorn + annotations: + storageclass.kubernetes.io/is-default-class: {{ .Values.persistence.defaultClass | quote }} + provisioner: driver.longhorn.io + allowVolumeExpansion: true + reclaimPolicy: "{{ .Values.persistence.reclaimPolicy }}" + volumeBindingMode: Immediate + parameters: + numberOfReplicas: "{{ .Values.persistence.defaultClassReplicaCount }}" + staleReplicaTimeout: "30" + fromBackup: "" + {{- if .Values.persistence.defaultFsType }} + fsType: "{{ .Values.persistence.defaultFsType }}" + {{- end }} + {{- if .Values.persistence.defaultMkfsParams }} + mkfsParams: "{{ .Values.persistence.defaultMkfsParams }}" + {{- end }} + {{- if .Values.persistence.migratable }} + migratable: "{{ .Values.persistence.migratable }}" + {{- end }} + {{- if .Values.persistence.nfsOptions }} + nfsOptions: "{{ .Values.persistence.nfsOptions }}" + {{- end }} + {{- if .Values.persistence.backingImage.enable }} + backingImage: {{ .Values.persistence.backingImage.name }} + backingImageDataSourceType: {{ .Values.persistence.backingImage.dataSourceType }} + backingImageDataSourceParameters: {{ .Values.persistence.backingImage.dataSourceParameters }} + backingImageChecksum: {{ .Values.persistence.backingImage.expectedChecksum }} + {{- end }} + {{- if .Values.persistence.recurringJobSelector.enable }} + recurringJobSelector: '{{ .Values.persistence.recurringJobSelector.jobList }}' + {{- end }} + dataLocality: {{ .Values.persistence.defaultDataLocality | quote }} + {{- if .Values.persistence.defaultNodeSelector.enable }} + nodeSelector: "{{ .Values.persistence.defaultNodeSelector.selector }}" + {{- end }} + {{- if .Values.persistence.removeSnapshotsDuringFilesystemTrim }} + unmapMarkSnapChainRemoved: "{{ .Values.persistence.removeSnapshotsDuringFilesystemTrim }}" + {{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/tls-secrets.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/tls-secrets.yaml new file mode 100644 index 0000000000..74c43426de --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/tls-secrets.yaml @@ -0,0 +1,16 @@ +{{- if .Values.ingress.enabled }} +{{- range .Values.ingress.secrets }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .name }} + namespace: {{ include "release_namespace" $ }} + labels: {{- include "longhorn.labels" $ | nindent 4 }} + app: longhorn +type: kubernetes.io/tls +data: + tls.crt: {{ .certificate | b64enc }} + tls.key: {{ .key | b64enc }} +--- +{{- end }} +{{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/uninstall-job.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/uninstall-job.yaml new file mode 100644 index 0000000000..1ab46207c3 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/uninstall-job.yaml @@ -0,0 +1,57 @@ +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": pre-delete + "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded + name: longhorn-uninstall + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-uninstall + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-uninstall + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - uninstall + - --force + env: + - name: LONGHORN_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: Never + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/userroles.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/userroles.yaml new file mode 100644 index 0000000000..1dbb6be90e --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/userroles.yaml @@ -0,0 +1,53 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-admin" + labels: + rbac.authorization.k8s.io/aggregate-to-admin: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "*" ] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-edit" + labels: + rbac.authorization.k8s.io/aggregate-to-edit: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "*" ] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-view" + labels: + rbac.authorization.k8s.io/aggregate-to-view: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "get", "list", "watch" ] diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/validate-install-crd.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/validate-install-crd.yaml new file mode 100644 index 0000000000..aac4dd9c53 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/validate-install-crd.yaml @@ -0,0 +1,35 @@ +#{{- if gt (len (lookup "rbac.authorization.k8s.io/v1" "ClusterRole" "" "")) 0 -}} +# {{- $found := dict -}} +# {{- set $found "longhorn.io/v1beta1/BackingImageDataSource" false -}} +# {{- set $found "longhorn.io/v1beta1/BackingImageManager" false -}} +# {{- set $found "longhorn.io/v1beta1/BackingImage" false -}} +# {{- set $found "longhorn.io/v1beta1/Backup" false -}} +# {{- set $found "longhorn.io/v1beta2/BackupBackingImage" false -}} +# {{- set $found "longhorn.io/v1beta1/BackupTarget" false -}} +# {{- set $found "longhorn.io/v1beta1/BackupVolume" false -}} +# {{- set $found "longhorn.io/v1beta1/EngineImage" false -}} +# {{- set $found "longhorn.io/v1beta1/Engine" false -}} +# {{- set $found "longhorn.io/v1beta1/InstanceManager" false -}} +# {{- set $found "longhorn.io/v1beta1/Node" false -}} +# {{- set $found "longhorn.io/v1beta2/Orphan" false -}} +# {{- set $found "longhorn.io/v1beta1/RecurringJob" false -}} +# {{- set $found "longhorn.io/v1beta1/Replica" false -}} +# {{- set $found "longhorn.io/v1beta1/Setting" false -}} +# {{- set $found "longhorn.io/v1beta1/ShareManager" false -}} +# {{- set $found "longhorn.io/v1beta2/Snapshot" false -}} +# {{- set $found "longhorn.io/v1beta2/SupportBundle" false -}} +# {{- set $found "longhorn.io/v1beta2/SystemBackup" false -}} +# {{- set $found "longhorn.io/v1beta2/SystemRestore" false -}} +# {{- set $found "longhorn.io/v1beta1/Volume" false -}} +# {{- set $found "longhorn.io/v1beta2/VolumeAttachment" false -}} +# {{- range .Capabilities.APIVersions -}} +# {{- if hasKey $found (toString .) -}} +# {{- set $found (toString .) true -}} +# {{- end -}} +# {{- end -}} +# {{- range $_, $exists := $found -}} +# {{- if (eq $exists false) -}} +# {{- required "Required CRDs are missing. Please install the corresponding CRD chart before installing this chart." "" -}} +# {{- end -}} +# {{- end -}} +#{{- end -}} diff --git a/charts/longhorn/105.0.1+up1.6.4/templates/validate-psp-install.yaml b/charts/longhorn/105.0.1+up1.6.4/templates/validate-psp-install.yaml new file mode 100644 index 0000000000..0df98e3657 --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/templates/validate-psp-install.yaml @@ -0,0 +1,7 @@ +#{{- if gt (len (lookup "rbac.authorization.k8s.io/v1" "ClusterRole" "" "")) 0 -}} +#{{- if .Values.enablePSP }} +#{{- if not (.Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy") }} +#{{- fail "The target cluster does not have the PodSecurityPolicy API resource. Please disable PSPs in this chart before proceeding." -}} +#{{- end }} +#{{- end }} +#{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.1+up1.6.4/values.yaml b/charts/longhorn/105.0.1+up1.6.4/values.yaml new file mode 100644 index 0000000000..f1898fe1bd --- /dev/null +++ b/charts/longhorn/105.0.1+up1.6.4/values.yaml @@ -0,0 +1,507 @@ +# Default values for longhorn. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. +global: + # -- Toleration for nodes allowed to run user-deployed components such as Longhorn Manager, Longhorn UI, and Longhorn Driver Deployer. + tolerations: [] + # -- Node selector for nodes allowed to run user-deployed components such as Longhorn Manager, Longhorn UI, and Longhorn Driver Deployer. + nodeSelector: {} + cattle: + # -- Default system registry. + systemDefaultRegistry: "" + windowsCluster: + # -- Setting that allows Longhorn to run on a Rancher Windows cluster. + enabled: false + # -- Toleration for Linux nodes that can run user-deployed Longhorn components. + tolerations: + - key: "cattle.io/os" + value: "linux" + effect: "NoSchedule" + operator: "Equal" + # -- Node selector for Linux nodes that can run user-deployed Longhorn components. + nodeSelector: + kubernetes.io/os: "linux" + defaultSetting: + # -- Toleration for system-managed Longhorn components. + taintToleration: cattle.io/os=linux:NoSchedule + # -- Node selector for system-managed Longhorn components. + systemManagedComponentsNodeSelector: kubernetes.io/os:linux + +networkPolicies: + # -- Setting that allows you to enable network policies that control access to Longhorn pods. + enabled: false + # -- Distribution that determines the policy for allowing access for an ingress. (Options: "k3s", "rke2", "rke1") + type: "k3s" + +image: + longhorn: + engine: + # -- Repository for the Longhorn Engine image. + repository: rancher/mirrored-longhornio-longhorn-engine + # -- Specify Longhorn engine image tag + tag: v1.6.4 + manager: + # -- Repository for the Longhorn Manager image. + repository: rancher/mirrored-longhornio-longhorn-manager + # -- Specify Longhorn manager image tag + tag: v1.6.4 + ui: + # -- Repository for the Longhorn UI image. + repository: rancher/mirrored-longhornio-longhorn-ui + # -- Specify Longhorn ui image tag + tag: v1.6.4 + instanceManager: + # -- Repository for the Longhorn Instance Manager image. + repository: rancher/mirrored-longhornio-longhorn-instance-manager + # -- Specify Longhorn instance manager image tag + tag: v1.6.4 + shareManager: + # -- Repository for the Longhorn Share Manager image. + repository: rancher/mirrored-longhornio-longhorn-share-manager + # -- Specify Longhorn share manager image tag + tag: v1.6.4 + backingImageManager: + # -- Repository for the Backing Image Manager image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-backing-image-manager + # -- Specify Longhorn backing image manager image tag + tag: v1.6.4 + supportBundleKit: + # -- Repository for the Longhorn Support Bundle Manager image. + repository: rancher/mirrored-longhornio-support-bundle-kit + # -- Tag for the Longhorn Support Bundle Manager image. + tag: v0.0.48 + csi: + attacher: + # -- Repository for the CSI attacher image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-attacher + # -- Tag for the CSI attacher image. When unspecified, Longhorn uses the default value. + tag: v4.7.0-20241219 + provisioner: + # -- Repository for the CSI Provisioner image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-provisioner + # -- Tag for the CSI Provisioner image. When unspecified, Longhorn uses the default value. + tag: v3.6.4-20241219 + nodeDriverRegistrar: + # -- Repository for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-node-driver-registrar + # -- Tag for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value. + tag: v2.12.0-20241219 + resizer: + # -- Repository for the CSI Resizer image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-resizer + # -- Tag for the CSI Resizer image. When unspecified, Longhorn uses the default value. + tag: v1.12.0-20241219 + snapshotter: + # -- Repository for the CSI Snapshotter image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-snapshotter + # -- Tag for the CSI Snapshotter image. When unspecified, Longhorn uses the default value. + tag: v6.3.4-20241219 + livenessProbe: + # -- Repository for the CSI liveness probe image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-livenessprobe + # -- Tag for the CSI liveness probe image. When unspecified, Longhorn uses the default value. + tag: v2.14.0-20241219 + openshift: + oauthProxy: + # -- Repository for the OAuth Proxy image. Specify the upstream image (for example, "quay.io/openshift/origin-oauth-proxy"). This setting applies only to OpenShift users. + repository: "" + # -- Tag for the OAuth Proxy image. Specify OCP/OKD version 4.1 or later (including version 4.15, which is available at quay.io/openshift/origin-oauth-proxy:4.15). This setting applies only to OpenShift users. + tag: "" + # -- Image pull policy that applies to all user-deployed Longhorn components, such as Longhorn Manager, Longhorn driver, and Longhorn UI. + pullPolicy: IfNotPresent + +service: + ui: + # -- Service type for Longhorn UI. (Options: "ClusterIP", "NodePort", "LoadBalancer", "Rancher-Proxy") + type: ClusterIP + # -- NodePort port number for Longhorn UI. When unspecified, Longhorn selects a free port between 30000 and 32767. + nodePort: null + manager: + # -- Service type for Longhorn Manager. + type: ClusterIP + # -- NodePort port number for Longhorn Manager. When unspecified, Longhorn selects a free port between 30000 and 32767. + nodePort: "" + +persistence: + # -- Setting that allows you to specify the default Longhorn StorageClass. + defaultClass: true + # -- Filesystem type of the default Longhorn StorageClass. + defaultFsType: ext4 + # -- mkfs parameters of the default Longhorn StorageClass. + defaultMkfsParams: "" + # -- Replica count of the default Longhorn StorageClass. + defaultClassReplicaCount: 3 + # -- Data locality of the default Longhorn StorageClass. (Options: "disabled", "best-effort") + defaultDataLocality: disabled + # -- Reclaim policy that provides instructions for handling of a volume after its claim is released. (Options: "Retain", "Delete") + reclaimPolicy: Delete + # -- Setting that allows you to enable live migration of a Longhorn volume from one node to another. + migratable: false + # -- Set NFS mount options for Longhorn StorageClass for RWX volumes + nfsOptions: "" + recurringJobSelector: + # -- Setting that allows you to enable the recurring job selector for a Longhorn StorageClass. + enable: false + # -- Recurring job selector for a Longhorn StorageClass. Ensure that quotes are used correctly when specifying job parameters. (Example: `[{"name":"backup", "isGroup":true}]`) + jobList: [] + backingImage: + # -- Setting that allows you to use a backing image in a Longhorn StorageClass. + enable: false + # -- Backing image to be used for creating and restoring volumes in a Longhorn StorageClass. When no backing images are available, specify the data source type and parameters that Longhorn can use to create a backing image. + name: ~ + # -- Data source type of a backing image used in a Longhorn StorageClass. + # If the backing image exists in the cluster, Longhorn uses this setting to verify the image. + # If the backing image does not exist, Longhorn creates one using the specified data source type. + dataSourceType: ~ + # -- Data source parameters of a backing image used in a Longhorn StorageClass. + # You can specify a JSON string of a map. (Example: `'{\"url\":\"https://backing-image-example.s3-region.amazonaws.com/test-backing-image\"}'`) + dataSourceParameters: ~ + # -- Expected SHA-512 checksum of a backing image used in a Longhorn StorageClass. + expectedChecksum: ~ + defaultNodeSelector: + # -- Setting that allows you to enable the node selector for the default Longhorn StorageClass. + enable: false + # -- Node selector for the default Longhorn StorageClass. Longhorn uses only nodes with the specified tags for storing volume data. (Examples: "storage,fast") + selector: "" + # -- Setting that allows you to enable automatic snapshot removal during filesystem trim for a Longhorn StorageClass. (Options: "ignored", "enabled", "disabled") + removeSnapshotsDuringFilesystemTrim: ignored + +preUpgradeChecker: + # -- Setting that allows Longhorn to perform pre-upgrade checks. Disable this setting when installing Longhorn using Argo CD or other GitOps solutions. + jobEnabled: true + # -- Setting that allows Longhorn to perform upgrade version checks after starting the Longhorn Manager DaemonSet Pods. Disabling this setting also disables `preUpgradeChecker.jobEnabled`. Longhorn recommends keeping this setting enabled. + upgradeVersionCheck: true + +csi: + # -- kubelet root directory. When unspecified, Longhorn uses the default value. + kubeletRootDir: ~ + # -- Replica count of the CSI Attacher. When unspecified, Longhorn uses the default value ("3"). + attacherReplicaCount: ~ + # -- Replica count of the CSI Provisioner. When unspecified, Longhorn uses the default value ("3"). + provisionerReplicaCount: ~ + # -- Replica count of the CSI Resizer. When unspecified, Longhorn uses the default value ("3"). + resizerReplicaCount: ~ + # -- Replica count of the CSI Snapshotter. When unspecified, Longhorn uses the default value ("3"). + snapshotterReplicaCount: ~ + +defaultSettings: + # -- Endpoint used to access the backupstore. (Options: "NFS", "CIFS", "AWS", "GCP", "AZURE") + backupTarget: ~ + # -- Name of the Kubernetes secret associated with the backup target. + backupTargetCredentialSecret: ~ + # -- Setting that allows Longhorn to automatically attach a volume and create snapshots or backups when recurring jobs are run. + allowRecurringJobWhileVolumeDetached: ~ + # -- Setting that allows Longhorn to automatically create a default disk only on nodes with the label "node.longhorn.io/create-default-disk=true" (if no other disks exist). When this setting is disabled, Longhorn creates a default disk on each node that is added to the cluster. + createDefaultDiskLabeledNodes: ~ + # -- Default path for storing data on a host. The default value is "/var/lib/longhorn/". + defaultDataPath: ~ + # -- Default data locality. A Longhorn volume has data locality if a local replica of the volume exists on the same node as the pod that is using the volume. + defaultDataLocality: ~ + # -- Setting that allows scheduling on nodes with healthy replicas of the same volume. This setting is disabled by default. + replicaSoftAntiAffinity: ~ + # -- Setting that automatically rebalances replicas when an available node is discovered. + replicaAutoBalance: ~ + # -- Percentage of storage that can be allocated relative to hard drive capacity. The default value is "100". + storageOverProvisioningPercentage: ~ + # -- Percentage of minimum available disk capacity. When the minimum available capacity exceeds the total available capacity, the disk becomes unschedulable until more space is made available for use. The default value is "25". + storageMinimalAvailablePercentage: ~ + # -- Percentage of disk space that is not allocated to the default disk on each new Longhorn node. + storageReservedPercentageForDefaultDisk: ~ + # -- Upgrade Checker that periodically checks for new Longhorn versions. When a new version is available, a notification appears on the Longhorn UI. This setting is enabled by default + upgradeChecker: ~ + # -- Default number of replicas for volumes created using the Longhorn UI. For Kubernetes configuration, modify the `numberOfReplicas` field in the StorageClass. The default value is "3". + defaultReplicaCount: ~ + # -- Default Longhorn StorageClass. "storageClassName" is assigned to PVs and PVCs that are created for an existing Longhorn volume. "storageClassName" can also be used as a label, so it is possible to use a Longhorn StorageClass to bind a workload to an existing PV without creating a Kubernetes StorageClass object. The default value is "longhorn-static". + defaultLonghornStaticStorageClass: ~ + # -- Number of seconds that Longhorn waits before checking the backupstore for new backups. The default value is "300". When the value is "0", polling is disabled. + backupstorePollInterval: ~ + # -- Number of minutes that Longhorn keeps a failed backup resource. When the value is "0", automatic deletion is disabled. + failedBackupTTL: ~ + # -- Setting that restores recurring jobs from a backup volume on a backup target and creates recurring jobs if none exist during backup restoration. + restoreVolumeRecurringJobs: ~ + # -- Maximum number of successful recurring backup and snapshot jobs to be retained. When the value is "0", a history of successful recurring jobs is not retained. + recurringSuccessfulJobsHistoryLimit: ~ + # -- Maximum number of failed recurring backup and snapshot jobs to be retained. When the value is "0", a history of failed recurring jobs is not retained. + recurringFailedJobsHistoryLimit: ~ + # -- Maximum number of snapshots or backups to be retained. + recurringJobMaxRetention: ~ + # -- Maximum number of failed support bundles that can exist in the cluster. When the value is "0", Longhorn automatically purges all failed support bundles. + supportBundleFailedHistoryLimit: ~ + # -- Taint or toleration for system-managed Longhorn components. + # Specify values using a semicolon-separated list in `kubectl taint` syntax (Example: key1=value1:effect; key2=value2:effect). + taintToleration: ~ + # -- Node selector for system-managed Longhorn components. + systemManagedComponentsNodeSelector: ~ + # -- PriorityClass for system-managed Longhorn components. + # This setting can help prevent Longhorn components from being evicted under Node Pressure. + # Notice that this will be applied to Longhorn user-deployed components by default if there are no priority class values set yet, such as `longhornManager.priorityClass`. + priorityClass: &defaultPriorityClassNameRef "longhorn-critical" + # -- Setting that allows Longhorn to automatically salvage volumes when all replicas become faulty (for example, when the network connection is interrupted). Longhorn determines which replicas are usable and then uses these replicas for the volume. This setting is enabled by default. + autoSalvage: ~ + # -- Setting that allows Longhorn to automatically delete a workload pod that is managed by a controller (for example, daemonset) whenever a Longhorn volume is detached unexpectedly (for example, during Kubernetes upgrades). After deletion, the controller restarts the pod and then Kubernetes handles volume reattachment and remounting. + autoDeletePodWhenVolumeDetachedUnexpectedly: ~ + # -- Setting that prevents Longhorn Manager from scheduling replicas on a cordoned Kubernetes node. This setting is enabled by default. + disableSchedulingOnCordonedNode: ~ + # -- Setting that allows Longhorn to schedule new replicas of a volume to nodes in the same zone as existing healthy replicas. Nodes that do not belong to any zone are treated as existing in the zone that contains healthy replicas. When identifying zones, Longhorn relies on the label "topology.kubernetes.io/zone=" in the Kubernetes node object. + replicaZoneSoftAntiAffinity: ~ + # -- Setting that allows scheduling on disks with existing healthy replicas of the same volume. This setting is enabled by default. + replicaDiskSoftAntiAffinity: ~ + # -- Policy that defines the action Longhorn takes when a volume is stuck with a StatefulSet or Deployment pod on a node that failed. + nodeDownPodDeletionPolicy: ~ + # -- Policy that defines the action Longhorn takes when a node with the last healthy replica of a volume is drained. + nodeDrainPolicy: ~ + # -- Setting that allows automatic detaching of manually-attached volumes when a node is cordoned. + detachManuallyAttachedVolumesWhenCordoned: ~ + # -- Number of seconds that Longhorn waits before reusing existing data on a failed replica instead of creating a new replica of a degraded volume. + replicaReplenishmentWaitInterval: ~ + # -- Maximum number of replicas that can be concurrently rebuilt on each node. + concurrentReplicaRebuildPerNodeLimit: ~ + # -- Maximum number of volumes that can be concurrently restored on each node using a backup. When the value is "0", restoration of volumes using a backup is disabled. + concurrentVolumeBackupRestorePerNodeLimit: ~ + # -- Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the "volume-head-xxx.img" file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. This setting applies only to volumes created using the Longhorn UI. + disableRevisionCounter: ~ + # -- Image pull policy for system-managed pods, such as Instance Manager, engine images, and CSI Driver. Changes to the image pull policy are applied only after the system-managed pods restart. + systemManagedPodsImagePullPolicy: ~ + # -- Setting that allows you to create and attach a volume without having all replicas scheduled at the time of creation. + allowVolumeCreationWithDegradedAvailability: ~ + # -- Setting that allows Longhorn to automatically clean up the system-generated snapshot after replica rebuilding is completed. + autoCleanupSystemGeneratedSnapshot: ~ + # -- Setting that allows Longhorn to automatically clean up the snapshot generated by a recurring backup job. + autoCleanupRecurringJobBackupSnapshot: ~ + # -- Maximum number of engines that are allowed to concurrently upgrade on each node after Longhorn Manager is upgraded. When the value is "0", Longhorn does not automatically upgrade volume engines to the new default engine image version. + concurrentAutomaticEngineUpgradePerNodeLimit: ~ + # -- Number of minutes that Longhorn waits before cleaning up the backing image file when no replicas in the disk are using it. + backingImageCleanupWaitInterval: ~ + # -- Number of seconds that Longhorn waits before downloading a backing image file again when the status of all image disk files changes to "failed" or "unknown". + backingImageRecoveryWaitInterval: ~ + # -- Percentage of the total allocatable CPU resources on each node to be reserved for each instance manager pod when the V1 Data Engine is enabled. The default value is "12". + guaranteedInstanceManagerCPU: ~ + # -- Setting that notifies Longhorn that the cluster is using the Kubernetes Cluster Autoscaler. + kubernetesClusterAutoscalerEnabled: ~ + # -- Setting that allows Longhorn to automatically delete an orphaned resource and the corresponding data (for example, stale replicas). Orphaned resources on failed or unknown nodes are not automatically cleaned up. + orphanAutoDeletion: ~ + # -- Storage network for in-cluster traffic. When unspecified, Longhorn uses the Kubernetes cluster network. + storageNetwork: ~ + # -- Flag that prevents accidental uninstallation of Longhorn. + deletingConfirmationFlag: ~ + # -- Timeout between the Longhorn Engine and replicas. Specify a value between "8" and "30" seconds. The default value is "8". + engineReplicaTimeout: ~ + # -- Setting that allows you to enable and disable snapshot hashing and data integrity checks. + snapshotDataIntegrity: ~ + # -- Setting that allows disabling of snapshot hashing after snapshot creation to minimize impact on system performance. + snapshotDataIntegrityImmediateCheckAfterSnapshotCreation: ~ + # -- Setting that defines when Longhorn checks the integrity of data in snapshot disk files. You must use the Unix cron expression format. + snapshotDataIntegrityCronjob: ~ + # -- Setting that allows Longhorn to automatically mark the latest snapshot and its parent files as removed during a filesystem trim. Longhorn does not remove snapshots containing multiple child files. + removeSnapshotsDuringFilesystemTrim: ~ + # -- Setting that allows fast rebuilding of replicas using the checksum of snapshot disk files. Before enabling this setting, you must set the snapshot-data-integrity value to "enable" or "fast-check". + fastReplicaRebuildEnabled: ~ + # -- Number of seconds that an HTTP client waits for a response from a File Sync server before considering the connection to have failed. + replicaFileSyncHttpClientTimeout: ~ + # -- Log levels that indicate the type and severity of logs in Longhorn Manager. The default value is "Info". (Options: "Panic", "Fatal", "Error", "Warn", "Info", "Debug", "Trace") + logLevel: ~ + # -- Setting that allows you to specify a backup compression method. + backupCompressionMethod: ~ + # -- Maximum number of worker threads that can concurrently run for each backup. + backupConcurrentLimit: ~ + # -- Maximum number of worker threads that can concurrently run for each restore operation. + restoreConcurrentLimit: ~ + # -- Setting that allows you to enable the V1 Data Engine. + v1DataEngine: ~ + # -- Setting that allows you to enable the V2 Data Engine, which is based on the Storage Performance Development Kit (SPDK). The V2 Data Engine is a preview feature and should not be used in production environments. + v2DataEngine: ~ + # -- Setting that allows you to configure maximum huge page size (in MiB) for the V2 Data Engine. + v2DataEngineHugepageLimit: ~ + # -- Setting that allows rebuilding of offline replicas for volumes using the V2 Data Engine. + offlineReplicaRebuilding: ~ + # -- Number of millicpus on each node to be reserved for each Instance Manager pod when the V2 Data Engine is enabled. The default value is "1250". + v2DataEngineGuaranteedInstanceManagerCPU: ~ + # -- Setting that allows scheduling of empty node selector volumes to any node. + allowEmptyNodeSelectorVolume: ~ + # -- Setting that allows scheduling of empty disk selector volumes to any disk. + allowEmptyDiskSelectorVolume: ~ + # -- Setting that allows Longhorn to periodically collect anonymous usage data for product improvement purposes. Longhorn sends collected data to the [Upgrade Responder](https://github.com/longhorn/upgrade-responder) server, which is the data source of the Longhorn Public Metrics Dashboard (https://metrics.longhorn.io). The Upgrade Responder server does not store data that can be used to identify clients, including IP addresses. + allowCollectingLonghornUsageMetrics: ~ + # -- Setting that temporarily prevents all attempts to purge volume snapshots. + disableSnapshotPurge: ~ + # -- Maximum snapshot count for a volume. The value should be between 2 to 250 + snapshotMaxCount: ~ + +privateRegistry: + # -- Setting that allows you to create a private registry secret. + createSecret: ~ + # -- URL of a private registry. When unspecified, Longhorn uses the default system registry. + registryUrl: ~ + # -- User account used for authenticating with a private registry. + registryUser: ~ + # -- Password for authenticating with a private registry. + registryPasswd: ~ + # -- Kubernetes secret that allows you to pull images from a private registry. This setting applies only when creation of private registry secrets is enabled. You must include the private registry name in the secret name. + registrySecret: ~ + +longhornManager: + log: + # -- Format of Longhorn Manager logs. (Options: "plain", "json") + format: plain + # -- PriorityClass for Longhorn Manager. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn Manager on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn Manager DaemonSet, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn Manager. Specify the nodes allowed to run Longhorn Manager. + nodeSelector: {} + ## If you want to set node selector for Longhorn Manager DaemonSet, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + # -- Annotation for the Longhorn Manager service. + serviceAnnotations: {} + ## If you want to set annotations for the Longhorn Manager service, delete the `{}` in the line above + ## and uncomment this example block + # annotation-key1: "annotation-value1" + # annotation-key2: "annotation-value2" + +longhornDriver: + log: + # -- Format of longhorn-driver logs. (Options: "plain", "json") + format: plain + # -- PriorityClass for Longhorn Driver. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn Driver on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn Driver Deployer Deployment, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn Driver. Specify the nodes allowed to run Longhorn Driver. + nodeSelector: {} + ## If you want to set node selector for Longhorn Driver Deployer Deployment, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + +longhornUI: + # -- Replica count for Longhorn UI. + replicas: 2 + # -- PriorityClass for Longhorn UI. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn UI on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn UI Deployment, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn UI. Specify the nodes allowed to run Longhorn UI. + nodeSelector: {} + ## If you want to set node selector for Longhorn UI Deployment, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + +ingress: + # -- Setting that allows Longhorn to generate ingress records for the Longhorn UI service. + enabled: false + + # -- IngressClass resource that contains ingress configuration, including the name of the Ingress controller. + # ingressClassName can replace the kubernetes.io/ingress.class annotation used in earlier Kubernetes releases. + ingressClassName: ~ + + # -- Hostname of the Layer 7 load balancer. + host: sslip.io + + # -- Setting that allows you to enable TLS on ingress records. + tls: false + + # -- Setting that allows you to enable secure connections to the Longhorn UI service via port 443. + secureBackends: false + + # -- TLS secret that contains the private key and certificate to be used for TLS. This setting applies only when TLS is enabled on ingress records. + tlsSecret: longhorn.local-tls + + # -- Default ingress path. You can access the Longhorn UI by following the full ingress path {{host}}+{{path}}. + path: / + + ## If you're using kube-lego, you will want to add: + ## kubernetes.io/tls-acme: true + ## + ## For a full list of possible ingress annotations, please see + ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/annotations.md + ## + ## If tls is set to true, annotation ingress.kubernetes.io/secure-backends: "true" will automatically be set + # -- Ingress annotations in the form of key-value pairs. + annotations: + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: true + + # -- Secret that contains a TLS private key and certificate. Use secrets if you want to use your own certificates to secure ingresses. + secrets: + ## If you're providing your own certificates, please use this to add the certificates as secrets + ## key and certificate should start with -----BEGIN CERTIFICATE----- or + ## -----BEGIN RSA PRIVATE KEY----- + ## + ## name should line up with a tlsSecret set further up + ## If you're using kube-lego, this is unneeded, as it will create the secret for you if it is not set + ## + ## It is also possible to create and manage the certificates outside of this helm chart + ## Please see README.md for more information + # - name: longhorn.local-tls + # key: + # certificate: + +# -- Setting that allows you to enable pod security policies (PSPs) that allow privileged Longhorn pods to start. This setting applies only to clusters running Kubernetes 1.25 and earlier, and with the built-in Pod Security admission controller enabled. +enablePSP: false + +# -- Specify override namespace, specifically this is useful for using longhorn as sub-chart and its release namespace is not the `longhorn-system`. +namespaceOverride: "" + +# -- Annotation for the Longhorn Manager DaemonSet pods. This setting is optional. +annotations: {} + +serviceAccount: + # -- Annotations to add to the service account + annotations: {} + +metrics: + serviceMonitor: + # -- Setting that allows the creation of a Prometheus ServiceMonitor resource for Longhorn Manager components. + enabled: false + # -- Additional labels for the Prometheus ServiceMonitor resource. + additionalLabels: {} + # -- Annotations for the Prometheus ServiceMonitor resource. + annotations: {} + # -- Interval at which Prometheus scrapes the metrics from the target. + interval: "" + # -- Timeout after which Prometheus considers the scrape to be failed. + scrapeTimeout: "" + # -- Configures the relabeling rules to apply the target’s metadata labels. See the [Prometheus Operator + # documentation](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.Endpoint) for + # formatting details. + relabelings: [] + # -- Configures the relabeling rules to apply to the samples before ingestion. See the [Prometheus Operator + # documentation](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.Endpoint) for + # formatting details. + metricRelabelings: [] + +## openshift settings +openshift: + # -- Setting that allows Longhorn to integrate with OpenShift. + enabled: false + ui: + # -- Route for connections between Longhorn and the OpenShift web console. + route: "longhorn-ui" + # -- Port for accessing the OpenShift web console. + port: 443 + # -- Port for proxy that provides access to the OpenShift web console. + proxy: 8443 + +# -- Setting that allows Longhorn to generate code coverage profiles. +enableGoCoverDir: false diff --git a/index.yaml b/index.yaml index b4e637e395..78350f8ccb 100755 --- a/index.yaml +++ b/index.yaml @@ -4640,6 +4640,49 @@ entries: urls: - assets/longhorn/longhorn-105.1.0+up1.7.2.tgz version: 105.1.0+up1.7.2 + - annotations: + catalog.cattle.io/auto-install: longhorn-crd=match + catalog.cattle.io/certified: rancher + catalog.cattle.io/display-name: Longhorn + catalog.cattle.io/kube-version: '>= 1.23.0-0' + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/permits-os: linux,windows + catalog.cattle.io/provides-gvr: longhorn.io/v1beta1 + catalog.cattle.io/rancher-version: '>= 2.10.0-0 < 2.11.0-0' + catalog.cattle.io/release-name: longhorn + catalog.cattle.io/type: cluster-tool + catalog.cattle.io/upstream-version: 1.6.4 + apiVersion: v1 + appVersion: v1.6.4 + created: "2025-03-02T13:05:33.130983964-03:00" + description: Longhorn is a distributed block storage system for Kubernetes. + digest: 6dae26cf47d97f2693173b45206a39f7013af041aca4a56ee890af2fa41f56aa + home: https://github.com/longhorn/longhorn + icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/longhorn/icon/color/longhorn-icon-color.png + keywords: + - longhorn + - storage + - distributed + - block + - device + - iscsi + - nfs + maintainers: + - email: maintainers@longhorn.io + name: Longhorn maintainers + name: longhorn + sources: + - https://github.com/longhorn/longhorn + - https://github.com/longhorn/longhorn-engine + - https://github.com/longhorn/longhorn-instance-manager + - https://github.com/longhorn/longhorn-share-manager + - https://github.com/longhorn/longhorn-manager + - https://github.com/longhorn/longhorn-ui + - https://github.com/longhorn/longhorn-tests + - https://github.com/longhorn/backing-image-manager + urls: + - assets/longhorn/longhorn-105.0.1+up1.6.4.tgz + version: 105.0.1+up1.6.4 - annotations: catalog.cattle.io/auto-install: longhorn-crd=match catalog.cattle.io/certified: rancher diff --git a/release.yaml b/release.yaml index 340c7480c6..0ec067e4b0 100644 --- a/release.yaml +++ b/release.yaml @@ -1,3 +1,4 @@ longhorn: - 105.1.1+up1.7.3 - 105.1.0+up1.7.2 + - 105.0.1+up1.6.4 From 1fd2c2d58f41bd9ebec499c0b03560abcb330c36 Mon Sep 17 00:00:00 2001 From: nicholasSUSE Date: Sun, 2 Mar 2025 13:05:43 -0300 Subject: [PATCH 5/9] fp: longhorn-105.0.0+up1.6.3 --- assets/longhorn/longhorn-105.0.0+up1.6.3.tgz | Bin 0 -> 30936 bytes charts/longhorn/105.0.0+up1.6.3/.helmignore | 21 + charts/longhorn/105.0.0+up1.6.3/Chart.yaml | 39 + charts/longhorn/105.0.0+up1.6.3/README.md | 50 + charts/longhorn/105.0.0+up1.6.3/app-readme.md | 27 + .../longhorn/105.0.0+up1.6.3/questions.yaml | 920 ++++++++++++++++++ .../105.0.0+up1.6.3/templates/NOTES.txt | 5 + .../105.0.0+up1.6.3/templates/_helpers.tpl | 66 ++ .../templates/clusterrole.yaml | 77 ++ .../templates/clusterrolebinding.yaml | 49 + .../templates/daemonset-sa.yaml | 167 ++++ .../templates/default-setting.yaml | 229 +++++ .../templates/deployment-driver.yaml | 132 +++ .../templates/deployment-ui.yaml | 182 ++++ .../105.0.0+up1.6.3/templates/ingress.yaml | 37 + ...king-image-data-source-network-policy.yaml | 27 + .../backing-image-manager-network-policy.yaml | 27 + .../instance-manager-networking.yaml | 27 + .../manager-network-policy.yaml | 35 + .../recovery-backend-network-policy.yaml | 17 + .../ui-frontend-network-policy.yaml | 46 + .../webhook-network-policy.yaml | 33 + .../templates/postupgrade-job.yaml | 56 ++ .../templates/preupgrade-job.yaml | 55 ++ .../templates/priorityclass.yaml | 9 + .../105.0.0+up1.6.3/templates/psp.yaml | 66 ++ .../templates/registry-secret.yaml | 13 + .../templates/serviceaccount.yaml | 40 + .../templates/servicemonitor.yaml | 40 + .../105.0.0+up1.6.3/templates/services.yaml | 47 + .../templates/storageclass.yaml | 50 + .../templates/tls-secrets.yaml | 16 + .../templates/uninstall-job.yaml | 57 ++ .../105.0.0+up1.6.3/templates/userroles.yaml | 53 + .../templates/validate-install-crd.yaml | 35 + .../templates/validate-psp-install.yaml | 7 + charts/longhorn/105.0.0+up1.6.3/values.yaml | 504 ++++++++++ index.yaml | 43 + release.yaml | 1 + 39 files changed, 3305 insertions(+) create mode 100644 assets/longhorn/longhorn-105.0.0+up1.6.3.tgz create mode 100644 charts/longhorn/105.0.0+up1.6.3/.helmignore create mode 100644 charts/longhorn/105.0.0+up1.6.3/Chart.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/README.md create mode 100644 charts/longhorn/105.0.0+up1.6.3/app-readme.md create mode 100644 charts/longhorn/105.0.0+up1.6.3/questions.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/NOTES.txt create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/_helpers.tpl create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/clusterrole.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/clusterrolebinding.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/daemonset-sa.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/default-setting.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/deployment-driver.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/deployment-ui.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/ingress.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/network-policies/backing-image-data-source-network-policy.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/network-policies/backing-image-manager-network-policy.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/network-policies/instance-manager-networking.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/network-policies/manager-network-policy.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/network-policies/recovery-backend-network-policy.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/network-policies/ui-frontend-network-policy.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/network-policies/webhook-network-policy.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/postupgrade-job.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/preupgrade-job.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/priorityclass.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/psp.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/registry-secret.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/serviceaccount.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/servicemonitor.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/services.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/storageclass.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/tls-secrets.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/uninstall-job.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/userroles.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/validate-install-crd.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/templates/validate-psp-install.yaml create mode 100644 charts/longhorn/105.0.0+up1.6.3/values.yaml diff --git a/assets/longhorn/longhorn-105.0.0+up1.6.3.tgz b/assets/longhorn/longhorn-105.0.0+up1.6.3.tgz new file mode 100644 index 0000000000000000000000000000000000000000..44fd9f2100890e8e1ab016f7a529a3cfe3ba1e3e GIT binary patch literal 30936 zcmV)FK)=5qiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMZ}cH20zI5_{Vo&s0t*-kR1{F!8~?l1SO+jhD=oy0o+=-#>A za}tPzB(y1l1AwyCnf%Va#=hP@$sQCw2!2VFEIXMQ^N++LfkL5BC{z^+g_tGd3FFE3 z(FAkZo8xKxhfO~_J3Bis4-Vk}ot>TX|9dYEcK@(@@M`zft5+}gUcC6j&hGxs!OK6O zosDBs^JGF|{)e4Aw^i=kKgolWgh?zZOGLkeP>3at*|-;CDPz*3Y#V2i1vC*7$8jH7 zb_qfry`EwjPHHQKgiAW2B6)qSx7w1T(?~Wl0}> z``@q8Zf|eDw-fAqTU%a%6e$jghqIUqNv5^MQ^KcIihzkeifNMFZr#u%VmG3`G-op! z5fO}MJcqBo%yx%F;@#R>h7!eI?DckcR4>r~Qh)9?cZidiU_lJ6;zhKQ^OW>a7-vEf z9!SRG+G1HMBqw;9BedIl+1u~nl>TJj%yv6CO}(E`A|fK>G?nnq4jZBZVH8mzIUQz_ zL}(bZ@EQrpI35$EsgFjCqaU*&;R%sM^g0u!`ZJL-75(k)F_n{S*bCWo+es$ZR~oAJ zY*CJHdb)Tf2oG5zNg|Wd=y!sg;(_f^C-8gQ33PweTQZ}e`bsZq0C<5pgdHz~c4) z)&9$uugdHH{@#nn_5UHBC+L`ra289X835$7lSG{-=yF1Z7VUpMeD^jOF+RmoN%s+r zi7IeR!WeUcW|&hvjEO*!p&>yj7J@{GCX%5!%Q%u`n#LG}{y1hs94m$62?_#q$zsAm z34!Jl77>AP9J3n|DQG-PkP`AiMADeeNrXZ+O<6(`DUis*3Bn>5mGAVF+{)ivoo*qV zMEQ$jPG^LpV-1e?ItWRJgXp7Q{$^2o&mw{ZiAg9K|8m%=MlTE&ee~(GUeIMs6b%ik zb|B3{%gI=+PV*j=&@WAqbMvW>x?T8cl$|53GH93v>IIRKCSxQgSn6JToiV*<3Bu@H zt2gLp4a@2uJp+s+iaDY_8sS(FzlGB1zg6m&p)xcY;-rSg4u_oBwkdxo&8q-i6V=^Z z`(dJMz9G%}ebfcbFMmx&BNEC!>b_?e;eBygua5GXN6eD85Eq1$E+X^#edJU2HK5SX$yRK(N}W|&)@AiH zijG`?_k|f!Aq!yC=_CZS!U2nENQrO~sE*6$EK>}w85fzFC^c2hD6&Ly79$*nM1bUT zxTh=vtSgMKC#%&Q74ZR7M5Ho85&%tfJ9D58;G?iJt-!kk(PYet5IywtEH!egd%Z8Z zTd2#g$)5RtxBE;nJN z$~(hvdrCQHoJ4_bjk2JuWcu%0Ae@hk^#S(IzTv6fsSugWjv&4!i+ppR(=S5onMXe^45E zXf7htCehQB+V8#W9l#rT z-95v4oCx}RJGML5MIV%G2E9du+7wz=Ogqwu1gB!cWZ7J8AkRf!{6R_Np}B}mn?z5O z>Sb@=%*vR~NJ4}da5h}3-792l1ts~0v5o^QvxmkArti@82hzT8;m7n2E zP6nLa&X@brP1Vt@Q;5!q>w8Uu|E4z^;@mv{-XDLZ8R72nb5UY~Q;TbSa$2185 zQ?(4-&YP%rR}`I+b#^q^KKt<)8Lu}w=JRxG4m{MKJH9)6sh-2b>6!$WBKP zKBFN_BWtc1{{g%QJ6rpEJcz!5Zd`1q17)78Wn{p(RDZu^IQkC9$~@ufw{fQhFj`>4 zTPxmy$eXu-5a@tOHXRaPMPtDf(cTz=FdA_}G?*cgH-sc;e`jZB2gtO)_v+=Vo?Gix zi+z-2aoj1{-%Ds>2BUY^PFXnj)U$54(@7QQ3P}<@=*yf%!b}if+T=RA-Zwmov4H7r z3c&9^l00+Xp*J)p#*GWqW22QIz7dx|RB|g1EXe8gNT3vRJSCEFu`0-S*CR1dwS{pS zTQL~Z5TlS~iCh&V{5BAd6o5Y3ckVGPF^XA;V=CwE0Q<8nq5_<5Y9bAZkO3Ku)I58Z zx2{@vYZ~YyTOsdQ7-KpuNFlrH4{ijWh0qu<Tfv>eq8ek0DNh$RFV9z<)x z{_R!OlTRcq_N*{mu)J^b|bo<>Q4zIIRu?Q94bC#vuzLFN7|MpR@3%{}9 zTPmd4xAJ{E?Fg9(f^f-ULX)*9_gw*q-U$Q}DB6XbV6A8*kuq*10~#CVSk$DJ@Chp- zsVR(Sn8pg3t)loG=emYAIK&OKz!=20 zUgUJJO!O}54V9A;M@l@_OHNU;z^LS0pcWnz!nHNRLK@{-xXr^{zgbQvoJlstl7`MB zfjF768IDnu0S+Tim*aH0coFgR0y<8V&8MWk*+Nu*I?YCF2~##B)_EX~p}|~tyySG+ zM+Q!(lX7yEjyaA9u!`2zTkY|ugpU}XqLh;$(;y7r_Rz6Ls3?PAl`}!3>bEzD>gORJ zGjw#UOh!;S(DziHr2+{S!-goZ(Qj;cVz*9x-MB5X7Ex<^YJ`niCM4$4inPj};4vms zmMC3kz#`X2UEDX9W5KNEDA30WeS3KqK6;GINyw&Cl0*Vs6OvZIn$cD?FnuubmjKof zqhq}HK$7chs1!uR8IvfY9Qb&?rccBGJ7-KDQ?8{+v$B75af%L&>wS#|(bMjJ_nB(e z`tOSd!ScpEhxVP?_x$IpqF|hycWU1FQde!-a~$5OdCyN-Mxj#-A<1JVPLe2PG?99l zQU-(xf-ovZmMSSr3PSDun+qkyj!yOehd;xA-yeZHFSr5kBLu)_ju}T z;XH;I2@-N55f*}l6syJ6tqmFwk^re!f_%hDL=s7Hd;t)=mX-+_C-!k1&kgT-re6|S zEz%NJC}C%)qQzsuWYL-|&k~pls=ag1Ec$suWAYQgJ|-|tqP1~#+O6e;h>B~yuCk=O zw8nTyV$@Y{dw!U^1`-$$fdcVbiKQ-jN=Hgf*J5407h11;X4tbJ>8Nmqca7dzK@kx} zWo@pizEXj36lvb`v|~j=4a0=H9aC}rR`rBLN(B)f?QG0kishuBIe>BtacvVOr1ohR z=MEL9yFJ5vJEp@tI=I^_x)=snPHNhVeE&ud9agOK2^Pgdh${UMej#qeftd=XiZK#bF}MhVRfSR9`wlJFUhYr8O|NhV3T3(5+F4Ju4w_Gz7! z6YVN%#3y$>M9N?@lE6nz1N=^_yq9mA)=ce*g*CFElEMxFw)hw=19YN-TJ5R36%e2e zCPp{09+A9*YRDDh#sX4UXf@Z@etm9uhi_q_%4Lqo!0H%fvDda~K_TYcGJubENORb7 zAyG4F(S!=v-EV3^_fD@N4xGQ6ap7vIF8rXuy`@ts7k0<+z&&-P0)1&W-aw6&x=?HK zl&~%B`@F-q=R_)7j3sTzV*(_R4v_RtRA@dcddnM0<0fEHX-qRd)+c-#nuEpPj}z5I zY9P=hRyH!@-m#Pw&OAJEF&E~1mR?3N5@bq47PBM}B*h%ome_Ru<8?M9p^Wt@jgLso z6NzsBaO7GXr;JlM&-WAC z60V@#DCU@uI7KNZGm^-){&^QLg zAA(h)!dZ~U<6*g`r9`DNnh9tN2}7yrI0~WXX7~k>Xij7v;quWgur?SX^$GS-ySBVH zee{2t77LVBipDt^dFyq^Da?q4&hTbGgTV1jsoqu%)Mi&4=SreB6%gPuM^Dwzn!T4T zT^jZv%(0u0B?$@bB1hFC%d=FH=$YqP^^VZoOlUaC+tNF++GC$6JDB7?F+qxot7jIs z(2&7llSy`=`@6PZ2G(%mD`mdHZkc^JN7x=ZiU}`KEdsx_Ao3Xykjx0L+4xsVg7G4u zEV0{1ad`;LV(n>t#u5mLW|$PY8&)ex z_LTB5yGaHtIyR!gMljtCO=!&XN())0Z($NB3CEqHsgEUKTE(SqWPPhji53${FvUrx z^oD{Y?DP=a0xXLtQc6=-sMEAgO2NRx3yFCHF;zVYP7|{fb2#EN|^9!5r=Om3uLIud@pD~p+hHh0~ciiv0Mnje;)t@9%yJ#~S%Yu6! zJov8AxkW$~j0S`&S+(2@vE#F#WiU9S;?9EAueIUQXgheutKV3$cG(`!o7X&`E%S4Y zM?=R7JnA-^b_~;65!s>N0~3-=Z54*n&RFtRU_AHOqG;HUTk{# zBl*=Acmz9ZhgD)?x52w5!l0M8g^L1G=b#9bnn1Vq&$licL0Pk%0aT zyg2xULes>=*uBLhs%(i`f8qqsEc-dxV6_@mOYbvKy_Rc9#qv#2J#CK6>z}Ed928Ef*!+1rJ@0%j|vD5MW9WS#23?A|oU>19sdqMuq3UyX|y zz+%{+mVGAR)y)#4&BDHvHfN!Ri)yeTzh+q26g zX?rA&ZFs4|7h>R0n9HxOR!_Q0yXbs1f>@5S2d7cRD1^R%tm{c{&ecK3I> zR+co)fj@V3A{+(YX!8bnVu_#;;f^%SQ z#waE;5*t)$646i@F`!S_V?%<>h@Cev8-p@dJ%w5?{7#b*>lT7w2RNZ&cMEmjV2NY( z#|h^QPW}FjIUEIqN^m4_n2psRmmG)sXkg67ZxzDrL}z|9#+U%gK(X_8O5}ujK@3Ov zw|DSqp$(u`F0d{+!I9@@DLPrQBv-ABPsMA`mR#=6S-mym-^m>uUX(#|%k7TF6xBcl zc($uv=-;b@+w;L~ncXWY&=3plpzWyTG6PgoX5#_8`49i^N_`j9Ik$&7NAOzqz4Y;V=R+ORIARqK(RWMhI- zNDQsk%BM6z@91~W+zwn3`Esj2WMiT#w;8>nm}R3;tf)~NtCox2YV)RIQ3TRt++YL7 zF%8qKrOi=EidM8aD&x4+=6IoFM}3lgzlH@;v)eI3WSYu(>2R2Hw(8v?>%@inC#t-^ zyRW@CYqY6jI2+njAB%0mhRG^zmW~m5VVNuj$0JTyGM}YFN}Ln#rP6KF(%D zZaO#YTsoYa5C1zdc=)huU~L0&a^xGfSo?KFa4{jh*c9 z8DztlhUguUoQ47&V=);r%p>Glp6XA2^uLiV6?E;2?Nlo*esv!`C%io_VmASeS|GL% zO~N>XiF!IfIEvI-q%|%Wpd(E;nv87+uGA0`l4;5~<}~)a;y8{Gmgojt@puc%*-VId2nuRL21mK8{R&MfbKI_IZqIQ_uQG2TSy%#&468#R}=BIB`PG?vW zm$G*SH!L!BT`FL6QYJqjQ91W=b^caw1eL3oT)NR_t5j^>jsS7*>_|3h z8a+{10Gy$w=Z;n0Brr5D}eE1F6eZKp_EnG@FE-1Tc zY_ePYCRk#Q+G@M8kKkK#pjTbKm{Kg$^98X?4cWyjD7&*OrJUXkfn_y`!r^4S;({BT zNWD)b{c`o~x>KfG)_VqF?!Wx)qa7+xRPd0^h;BtGYgwXCkD916<2y5VPe6}Ns_Sbq z*P&bWxvHOdd9UGr`?4YHbwkKs)e5@saxg5Wt2eAQ`OWL8T0N8Amad;Z-;J(16eYMO z^W8q`>K{6UvRnGTSNy)`$am;2+iA{6Y%)xNQ$_!I=v~pXh&0|+K1;!Gm^69QmOkE_ z0+EU(_i9S+b#n=%cRu?qM1N#86F>6K$PkomKv%BSPFVRPPEoO{Kb+@_Ma&`LPGv(^^Uu|++ovt!5^cZepQY@h4 z7o7*@l7rT%N^As#y&VA}fp}E2B3_;PYi;S41{c<&q3G%3HZ+SduC}Gp(Z$@Dg>m%4 zQ%~~>CSY10DWG0skm>;L2q9^#53Q2YtrqtF2Yo&uUq+n=k6<2CQaD~|GSI>7D>nza zzv=f6Oh_N)w^&KaR|o>r&6#SzdcuV4BOzj%_9*MLcY9vGy-?z!G)y2BVo@H3<=_Mf zGwyE-xR{Tc0Y@{6btcGzgMF=OsoLM+@R}r1rFDg>Z}z#7_ie3fGS>&;^wo!Y51|;F zcKP;VsR5|k@&bVyDP+wx=a+%Z0D+7}r+kpr0!Xo(^jyv?FIk6Aq2U~jn7wZV0`b7A z^+2FcpVXj#{`{v;pVaTqpJ5$=JO|qyU-o?KqEz7a#+Zzm-jsr)GFC9*DC+B4MfR4l z2ym#_(q{j8qKmx&-wNOb2cDFvY>&QLL_J-23#GvGNDw2nI2qO6IGDF@=T?x6X>z+g zjM>m$Bp9(!Y_s? zktG3DQ2vduhAc>Iq&QQ{Q%K8 zK|h}S6~1`v1|r%t0&8=YTK|@l5x|L~j6+72EL}Q5rMd7eOA zk`iocpy7mRbgGtEu)-O2FIrTGT2*PxGAU?eRv{|Tgv3)6PB7Qt(ZJ1Y zbbfMp{O+VT)uI+sP0&O;nkX|)CRDsR)03H6XHy!V`O`zA-|4hmgi;o1UZirKUljFp za4`_iylOBBXiN&H7a<~7@iK(uE)H8Z0YyS7gGuR-)^2a_1<=&2{yK~}Pl%M!SOzpf z0~V=ys&U29lnN6|?hbLeJY@Qh!NtHWjG7)sO=UB}xf&&R=dMk}X(X28C_zS9Y%+Z) zv}1PwS0IrM0~lEs-C=Z<9IWLo&`L|U`hM(nT)8uYkj~)T+VhfUeS@pJDu;7)wp$$c zI=JMKv1!2%wIjP<_4njrgqg{s6%ph5E{SA-X?9-vxg+QuOX%`EjxdQlH!?;8&Zb08 zNG5DfZUZUTXlos5<=fY4uJF^{j3TN@qgDA_*QfL`(++T5ptZGJq)*6#ZW)CzQ6e#o4F~2OwGM-o3Bv3tyi~n6(M2>F69FM2|7;Y|+<9K2OXtax{2~i0 z!$hZWw?!*+TE~c~Wg1oxcOgWL$y~Y-;hbes%N5@yv%8*o>ID-UoL@C@LxwOzSZt;+ zSCIPN$@GkRQvq%WfNef7Xsp??0A32o{SOZIYk?YWHPn{=YbQoc|B=eEPKg9L?youiXSRCUTyV z*HcB7a6Q8&nektBk@HG)Uw)V8BcnV)~paIEvg<1{sK zFFz9v9m-49hUy07q`{dWNU&)!afCt>(hcfkMlqdImo$i$s#e-vHRJJ+_euBpMUM9+GR&55|vfrql~g+lwO z4MM8xWbau8TP3Xf+uMH>*74c@&lfv8T@UE`NNe|07nPd)^lKMqaw2~1_R*(byMMHQ zsF&(b{p$1Q&s|6GQUqSli)2GjbHew5@XP85!j~4(;b-U{X!!DgB;hmn7xH?nxjsPK z&pWw4OIzPos}%N7W)fi@p&v**wT55k`L;hJi^HtTXaeIjExD?-5AD+@WLJ#JRPQO| zCM2Hr#AF-91C;lf`Sa%>e`C_yqkp)~uI`_@sQUp1uZn;p7J5;gCU?ZStQ$F<#9G({Go-=?C6wu^FXCUUPlIF(*)KkwL{!Jf94 zc&O-ateYgJ&<9tjmL3&Xq${+%L}8Q)oT{Cmi$-nr^}j~{Ga5fvcI_Nb@2&$b(f?i^ z>>rf$znA+j_8;}Xhj?&Gf3l*E4{_L23nAn5cYR{&`p;S#?sl$e61i&{&sj`5)|uGv zpwh-lpm?Wa0y~6~p#iF@26mb0p?{!+CJ{*_I#9D0Tz36VfN)CTx-)Qs!%uQ6Nuo1h zYt;0SE`2s!mkKi>+0?#-c?-T}(LrcN_|O#VKJOMNC=iR?8@3<3BrOIOhmzBm;$SN3|rlJbUB_-6TnapDLx91R8 zislf@a8hmHH#XEX(8rCJ!_nDtYDYVwf@iSLGt8o~!BGu{*(tM|dQ02Lk1rWUt!d80 z*uf@y8RQN0wUN{&e?TK_^WB2pvPqfp6pQsQJ=P2bb?g`ls;|p!(Q$K#rMC=4Gk;9+ z3a0K5PW4sD5?Sm)`HStwGGsk3Q6qw0D;{-BVj1sG@1qUG^#ArgTYr3a%iM!(9|KCC zA<04O-*r+0{_s9nE!P-oweMW<4nifh#qAIDZ2ZyZ&x=sp9?=Axa@@nF_^#5r|Jh(* z%$ZU{VuE?0BZU`Ur%lS3oN9#^es>G-{Zf82b?+NmQ>&k0m<68}VvwbJd(HuHFG_7@ zsmG6n7nOqkpN);X+)!407G8KTb;cC`PoI_jS?Yc?HfpkFn>^Z3r|`yy3<|#2p~8zw zL7T(A`lbkTD+7#MiZ|a!5yPE`?=JYBnx6MwijTW0h5%8tZB? znmDCSJt;s3uv^G1X;t_(_M}xS(@erKz8f-}Fm_#txzz)RV;U_e(%5m(APANOmVCSX z>Okl!){VMy6=kIi>lwykGNh3GNUy57q1EuZX4Kn=>>vm__oLXeFb(qPrOoU4N`Ww{ zme;jf4aXFNCI42f{EBy|)gx_Lu$zI+l6giWt!i8Ri`2~oG4wSH(wDZ)9^zSS{~NZv zqZ?p}{lE8ew`~8vdbP9nX#YRNv%Z-4PV>ehX`$HX4&s5uE7JV_SIQRSQd%&-z8O)sqJN1A(z2n9-g{ei^YsZT7$*T9lSG!dQm4LfX)o}4 zT>1s|jhgk}IqU*~H?je+c>UkqfA#7`#sB~6G5+I09$)z3G!?m=bK&p>@wTSqf>7)< z^(L}$tyE`t@xux;Nu(sy(emaftPYS>mYj(yHy(f{MC=sk+sIniYxS(&^FRAut)@oR zqd-D@tzE19(_9Wl>CjeQRkFY0Y24Iw$-`!;q#koNi*N_9d_<;%DAM_DO56X%?O`<* zpFX*+K!sj8grvtw$^?ab={|q%FE20g*rz5fr>Cz#NZm)jp0yf}wAI-6d_wsm=uRA3 zDov+2iSn{RGkF3OM1`@TBSil0P%Gcn6|-?qM|PY1I6kfc3VtiVD)~tRbKjF+A<*vG z0BGQS=&n6r8er@3GR5_9bqlCjSFk1829c!2jCQTDE!V3<8{E$KfHS~d72!gqI&6&_ zQsa3KSo`_eS4F(#3&m8-RO zE44zFShQ{?3+wJx>N+R(va0))s&G|}4S;lCIl&Q4h!6wLhQwc|CQ_!~lfu&Fj^EFA zxAnbPzZbvObs9m6O@+Y^mzRSJ_eJl3yo1OApYYZ=nt3qbg1&)nd%}d=j>v4gQYYms zTvSPYuhz2c*idtZ`F2c)c|OcaInGi%HVMr$5E70Xn+nD}4b6Grx;AAj0yvnn z-83i4=XHwfwQg<90yyatM3gr)tpygxfWf!=MVsg#7hghjAVaF;>- z{_N=Nr<3#J)AKT3?T6Fs=azMGf6A%(0+{=XtL7PR>eWuX1y%hC*f{+b)Nh)Lt?9UM zYAk5Dp0EfKxA)O8OnJuVXIvi*sJDpP$N?RL?a0mYOJnIF>3mT zCK0=_cj8oIU;H#>Wf_5!Xf>#<3i~+gz-MdYuUh*b$an-^`ckWACD|B_HNNfy%iVze z!*;x7Kiad7pERuzmD)n9F;5{m+rw~A0qfP-r%>I|{m<+2&+3F;$U&=vtMbs|zEoZm zvwOT>w)2st5tigaaxBSsuE(6SIHt+?3O-pjnBv>31nY|nW70?6-JP93b}M^Q&LeB~ zD<0S%n_DI;`eT=_CDr`4x>~`}S!Lc9VBAO_>xZzZ{|Dz{fV8T@Iz6G>+ z|7ZWjtNrr%|5v-akMSQ5^3)0%olWH(P8aQLm)K+-`LL$&vIx~NY9IY0@TXG3BzmfP zbt+JoCJ-H%A3rk?OqveS)1jP~Fgu^w38P;Idd?Q6+M?<;(`_SY9dQEpW?*9k)T0@M zu2^7fm$rzP8`xw=AO(tl}KR9pwKE*L<7?!rDTY-5w1F~5(o#L5D9 z=sUcz#DTWO7ob~$vPlHZ>52U~R511cj zl6|N1=~j@&nPh=Uw%Z0>57s6zH3xalW`qwo(-)xAWSn2W>kv0318~WtUfCdZg%@^Y zX;b&muXi+|Qyd>!J$ymGrn+e0boLed)!fuQ^y}Q*GL|>;hH+13RC;HxCG$EJj2JHn zsW!b_*6=3#niV#nT$k)NQ>foB#JULL9;Bzq+YeVdRV1jL>pF2{3n}VDyC+fqmW4R> zrD#Fi$L4EWk#C{h1F|;T)P=J9LUTPLI29|X=k_|34J^}}49Cm6(%jbOH9a`EG+=RT zlT?CWYeRbx- zUM+3!Ub^=eHhhO~&xurK2uo`Eq)dS+z74o7)2<&S!1sdu8(`rU<6>sUx?@t`&PMeJ zKiEY#SKFmhxQ^*p`z|eMXK|MpM^9Jlmc%rX`5iXTo}s6!xZqv40Zx!_RzM%WF_n%B zjb0X;ME%$L<^qWM`6g;rHYjgt+|S-Y5t%ZvJS;RG?fUzA!)^O1ZwfTI8z)qIw|Hn? zw}reE^>4}*?5MY+?-D$L&3I7c1!?t| zP;1y5?*PZN9&PoZHL5w3&3e|9h zzxbRCGa5$&!j*(98t{4HAnzj-4^qOlKE2$GZ`0)cbWt;i_8OjRPu#M8nw8bKC9UIc zt==wa{T|lWbE0>~U=P6C^{~q-H{bQ9!jkQedYBvaBl&vtfJNf8czCnPq)S;O%sI9+ zi{mzeaamIvk7dwC!!x z6%g38c6$^PoMh<*ko$X+Zalg$`QM64ZK%tdd)fkq?!@;`Gzid*1@NdneG5 z&IZ4f2qtU%>YX$VY}OSqWiw()C5|)L=%+E!y7MKcQ_mZr%DT}KL6qsR0#`hcoKBZ` zB$l?f*%%>F@(q+1KvkmRgJ`qvHG;kePmv?P{s6 zm4}5G`t>)8*Ipf7d+qVsyMMfX$i^hak7RSaD*e!}HGz=js?rzfz*x4b8M6LGDc zR9o11PmWlu;L~Jm!@92o9+P+a3WZXKLRUDCBF_Yz2hru1_iJ%`_pt?Ubh<&t$2I%z zRu@jy=T=+oKD_&qPv5t3`IN-fT|7W-+rAH5!~{~ zU@zF}qute$|5nj|z$C!c#*68BX+q^uB}H$ZU;-TXjj3qAnq0kk23_>aw_@_`7Wy^_ z)xU6<8~uX5c^YOsM!^*AqClX4>11X}7RM;KLES%oQs(oAkVWKk7nw_=%lS#*>ges+ z?lbfsuTghzXQzw)_FpJsh=dacq@v0AzmSLtNztDAl8|rz*0BgSQ+eTVePx7RH!X5a zlH-MGj!TJ-Ar~=_#Sp1jupuMr*O3#oh+)R#!j~n?=9MjEVqBh!u`y|3bK1hT85tMn zO1x{s^%)cMHZM-je>y!n`EYo2bawUra?>qWb1`{UJ{8mFgo46`SWM(OW3rUFF-Q5w ztM5+Uo?L!7KRdhpP|V=yayWX7wG8a1x+@K94hd)mRnSbxT!EPvl&Va7+mWM-(+`K2 zmxo6`oSc6+eRueM&A|6ppL0zp*3GvXM7wvQjY}i2j68n9g%lc`pZ#=taeDTC<3wt} zwTVtujPFJ&9TuwOuSxremyoQk!a~x4Ksi1?{psZV!}-bgrx%y!hnptil3p|sv$-#K zBPu6?{=SU&Y@vn3J3qNN{hy8VTn&CrBr0NgH?mm!Q!XQoUvMFLF5VvwE`B(>yxcg6 z8gOkQQx)U8kt(J$;xc(JCRVZNLUO%5{psZW$;E{dXWyM{m|~46H_@yP@wQa+*Hyc8 z)MdG-(!i~C=O=@=r$>h$8dQ$T@?G0ZB@gW?hqcI}@ar?plW z?v~QJ7REhgv^H%$CbYi4gw{1AUOS(44XiJe&e~w|n9cg0vsu^CdHrP8bHQaUa;1@uA>HU{4{Vd-9%jhO90A0HOSH1u9<<6_e{lABJ zKDD?cxv@+}dz@uj(Rl*Ca?#)39#c8VhP{wYw_VX~hBG+{QqFGY+ryX*x2IT%=k1Us zlGEX~pb-hN-fHeVL3+9(jG%^iHQy8gd`!Kr}7KkTi_9@`fjCt=*s=7Hj_S%(+MuJ0DMZuK}fhX z3ATgkP1Q0Mj@Fgy0gBk#D*~DZTYW|UaC*eS!M-Jjf0saGZD8@d`k!6>MRyxy6votB zExkWi4jlOEM!Xt8P-EX+o!VGzQAe<)0S0>JJX}nHVJ1I}V4=!ad!IUhwP`5-eR4~}45UWE8*xMEcp`Q9h6j>GwxvtLD?5fjmZ~LU z9~hUDTO05#swDz+P3FM5l}`wMvrI23SzIxYr*wO3vqO2!kcPZD06I`Gm-&xt>nywP`E>N2$pI&V zco&o|yDW5d@n|1&pI$bMX?~*~=Ho(Z0UYxX0gfWYcdz^Fwx>XWk2fOxwX0e9?B15A z@9X7L+g`;gBqwZI{V*xAO>un;#Z5fMghh_HVAPz@u^t8{uRD&L)r56u{jL5%4QJ|C{Pcjk7k$$JX>@JEzi8G zXO{_}!pyQvq2`}^*$_tb_U!%lKb)Pv|M2ec{o(f~=f$g5^Uc0R@k-rAaIa2349?DL zH$l1z>u$Z@=3dvO`q|R@GR~Ff7}2K>cprVrIaQ-lWym(gecoGGzQ|_(d^;&ur+3>$ zsnoxx9h9rn$K8{A+&w9gckP{%5}YrzYjSn^xMOnPJ0@isufJPThIEIWk{}35o~x2u z>;Bvtj*jH-u7}nQrL?bkN>KM4C*g$f04$}hg;umEZT=WjxsSS%XQbPy^u4syjyOx? zTGxGAm&2MJ&^tDU2SK|5G-E;h?=|;aTBuN}(6yRL=2eOrj?8UY{B(exE<*UNSGH@8 zY!&M_p;l^TA(E@0u%xLAux-w9GPW1OHGS2bTapiLpjH^V(5)qY#TtL8Q-f2ZDp$Ol zuEeMMYf>}1+6}2S<%>M$*H5xIF3+AXy?L{Nr)K|;CSy*7*u>7CeirZl?dYjum}RagJyN|K^)uE~50eFN4u>c6fafXnw|Be>S#nt-I% zM$@P2rPmEzH2*srO+zTZEjo7=RxR|EXE8C79^8v{VAKbTH~28D`H1DD;81awjanVC z+pPdgy-P-OFqfb}oKDl2Oi7{%dXbWljy#vH&ecMS2jScnO4;MztULJ+tY?+If+U*` z35RvAVN_&n#@lSXYVsLs1k0%CyF_Y=%2?#ae*F&LmljQr&jUO)>%S55I^QxSV!N0( z6tXX9-+53dI&ab#maPA~d#_68|My<)9=v>9{~zKh$sRMH12gn%=mGCN2=f|kpplu@ zw>VQ4T`b#`_cnjF-Ca?OvC&MemJK6*Po3^yq^N#9atB(2Dk=@=R238di1li48oE|a zhq5`yMWWp^cz;YD7pILstIL0TRKA_;|3e%3|FSIqU+%xyd6fST@qA(Vp9_yKE&Fp! z9_9X{-2b)PI!v z|AtQ+`MdTyHnzNT7$>(>NP#{t#d=w5ejk2g!$4wj zy;eiZC|yn$`E@R5ZREeZDa`DRt-25_k^eg{_Ft9c|BDy9kNW?EJYP=!m$~ZeUI@I% z{s5(%NfxrWk1mgF9KMcP`p*|T`(NoyuYcOi|BSk=?X`5kW$`~RcMi(-|BKzn^ZyU> z)Wk?O$$+L9p{I}m--}%=1JD7C-Dl74LyUOL`H&LC#4xU^MOK4j>xsp$$!_hu^>v!CcR`yiDZA%l zrZ-Mn_0imP{KW~YdK#=s-G)jlk@$LF{PR#)LzNtp5xsWt$KK(ow0d%{Zv796am)3^ zzP>=KHtYWl8BQ3xzBm8R-d=hCcmLJyqyOhYo-e2Whb)=`G4?of46-9)9&uxqx^q}$Cpw=B?WTH z^cOZP$fL@EiSC5N)1H`YD{0j2BgHs@;hbs#eGNP@+C#UG;HAjIkdTN(TSGEpoCNUJ zUOiovf~7Vd`m!k;N;)IQ1V=GV$OQ=*9P{{3P!5MUyk?`(TYYin?$X3hi@S#ImKw^> z09DN=R7tT=)A(0&uhF_mMk;q2Ex6GEm^f$0D5!ETDyQREcBfCn^)^kH+qAjOhZ7~9 zr0w`w@&?m5<9;I3f38ds=2peKrHiNsvOH(R8p&_h%7b9>d(1U)f4L^=XuNj9i8^3k zDC>kp3?v5Xas1Rp5w-kkeG(FVa2H_q@C{ z)lkYJfhKsSuX~x$@q`HJ9EV6UrD4qo+!8ZKSwe185=s&wGNbz5m*E_${^;UBY|jZt zSrQQrVirLhdB#b%qlLw>79o8!!m%KoloK)qB(2&s&~M(d8^SHYIwpzou4VR}uV?Q6 zp<(`ubaT1i{?H=+^Tn&u`On>hm%A?>=l?@IwHLMxE(Ya@4{cU&&vu7IVkZ??bYU)s zTOPlViuCSQv9c3rOvWVYBgr#mpx`)WHv{|rM1(jtR}+~6ocukboJ7Z*rAIi$LmE>_ zZTQ0blgkh1hd*0DB&rs<`0K@o!{c|S?>qV~Iuo*C1%ZBfIyfr67@QvGD7c&QKr7%` zO#0|ty*y0jkS+5qO|sjDuOsn2XIa`*H%o0wvlz;WhJs$|c1TP=qT_csgYZC7}nnW}i zFQehm6nj82vX~e*geByHPIc_=otJwDmH40i$NX;(@+@)ffv21lGexfC32e9!5LT3`=vvVu z_)tE1oqN0(Hy*L@nsB|0{w7$`u|4UPzmy!?dRA3sLH_4Mj(^SkH-gj1&HLZ~+uN_? ze}1*|c>e2Qo<$dS+7)ksigD*f_6~Z9s>)q@35?pk2+IT$}OP`Z5>hvtM?#X$wl# z-p2MXNvyWFLbbdR$`nhOTo?C}PqrxEMDb!*eHS7p5nLS(*IJS!Bx*UDVm|MqZ$EX_ z(0BXYv%^eI&P~a4Te7>=%{isp@6LANvN`*;@2bP)!QCym(9XM^F34#2^XG5tNV+*@ zR5l~yG8kq_6hGwd_Cqq_mlm!66i@T|KV=D(j6cBozjsj4|94(I#{WFXW2CE_jZ-2y z4c)AKXPCeW?x3X78z!O2xEC@`n1E~F%M!^zS?H_aY)a&WWFjc?-yMWge&Twy8zWXg ztwx?TP!LBERYDBM`kYm9hp<_m)vN=pn%mrZZhfyS-h5q?->K%%ne&R7D-BwVE=i)4 z(L{O&&HBiXvuR5snn=QDI7aSH5B*!)p|#|14_t&Cr{t1O3Cr?J8T^+UX@(PEWtxl~ zM|rRMi&^Z?cWhk0KChxs`LG5ej|=%jJk9I><}QF*w*K$DD#!o6c)9<0{_jDaMTW%v z+;iA??)#q3hF32ZTy!^`f6%#fL0v6Ug=62SbYY!eqqFywAJHhw=R%Qr^sI-Ck; z#>=$!DtswYH)J%smz-xCBXkW)g=A)BIzxF^_)Ckg$LEeu-TE&X$78aw@V}+!e=7HX z?7lpB^%(#2AWyB7JaWMyi+qS4n>?Tg(PC5K(mwhJ2rDD#_2(ml9mFE!fsXp47gvFn z9-6T>ZrO|mv(Cq*l#WXTCQu-N&&54Xg^-ZoU^b;{k20s6&8R}1@IKOcW&J$4x_@!Z zZhnFgpOf1ZC&CYbQbu7IV>-2=iroe*3dPXp&-&_09XVtoPTsKy?ophQh+?Usr0r48kKhV^@TZ%%V`Z{P#>6l}Qhq2fF z{9SYVg?iP7)vx7^CnIr|7Va}eD1X=7c%k09jhp)hPT@S4c5CKX_#Yc*Y5_vx?mR8m zKgJU43$riFSC=1c7LFF_ zIhylvxSSm|L3EZi|HTq=`29i;nvSE~^1oR!j%xP<6a*v2!zIZ%-k!bx{)e;k_g^SO z$9pn!{rHNrb37&ie9Rc~m@(urW5{F1kgqifV4eOi2vhx}{LuX83qK=46Z|2_(~X`=~2H{jLu-mt%m^*`RH~e% zwFsA9FGM>_b@Yl?*}SN<<#A2nMWvwsXJg}T^Wir(H0VI>|6V&{E zu4eTbsS(-=C=yY*rhHOWAH~z7czP61kK*aR#M6wDn>EFgs`@CN9>vq6c>4DhPh%og z>6i-m{|3u&q9%IP{;RS7XE>&j5+-&VFyzslTmeh$|NVn<{?EOgoyYsX9_D#s{AOc` zp2j3WPh-ZevlMj~EoNQR^%k-&>UQ<@&O2~E_z8Hhz8SGBiBSJFifAak4}wVh(O-vb zYQgRAYGd8HI=9}MaExE>Za~(nou#YR+cWhx(e@<>>ve1EaN^Z#pTO$9CgQsC>h(^| za=-Rizh}|P&F*cV!J@NzYv*2U;ySfKxmvyAg;v4VsHk+JHEFxIZ6p2GsHs=r?_dR9 zqdF|M>rO;n`&=*8tJ7?~`Lk#09lBM%3c&FK0P$%=D$#@IW z&qz8WD8+K(y~jz^d4du$24RAprksrEEs1odng4j!LuW}mM=XJw3MG^hj$)dSUZ;0_ z@!>)#VVx)Fh)t&~K|dW`pontO>5Zw}hJQ8so!;f_}oBvP_`U;}g;8nKbB~9*qdz*5x?+?VnLI zaP$BCvcL$o*?bPLPsnj zosR1=6=-*7=Z}b`BtcsFK!T0r4dzM<(IUov2w6l_4Uuw!BZNcFgh1FFvqo%$Al$m& z>FoA$s%lpX3IcSb#CpgQ$ypo|zHK&VP|U_OM7CdJDks?xQusN!knflSu+E+b-@06o z@eAmdDvj8U7!=bH3Fl!kemeyIFCQ)Y0rp*By{Vyj`M8BXh8d65|09}2(?qI2$DE|< ze|&TO5d_M|VSG)ak7$Ag8j@V#kVwf#B{^Z!Qq9%U?Ni29=_%&%8driLpdu8s4k##8 zTI@oZ=p%|SQThxOic(6%BG#^9^oDWt{f{SGklklGB}qggbT!NpnW^b9&WMoc?80!a zplUKxX{jrUxZ+sJsJWJXS5C}I<~OaV{o+rZ&V|HW!lXzlpSRF20~R4`t)YRrWhEEH zm6ZHqJ7h^nQYp6W-7MQFivs(@oIl!rrtLu>sXmJw>2;<=p~JyxuhThHqLvep#c~Th ze{Sr*Y*E*qKSxg)hXFt%PQ=8mpNbi(l(1v*Yzt+AaP91JSC>hqbm0->Q-l={1Zk`m zRdbE39$9Ce!kqZ%tnQEC*^>-?1W(&XWqnhbb5zR7OzF1q+!d5OBOkrxwEz5h=fBbE z2+djM8lAI@J2Sg(aIKvT^i^a6Q+h@*!sw$~H7%%*=qZ^g-qsCFagyOUo}(}(I6+yO zM<+Z}zj zM8YJxVf-3BH3-||LTct0x?sdgPf^Ozit7;(XiOv$G7GPrCjl_qGX0$!?*z-c47CgW zvPZHzS1C)738g5Evt-(tx~02nm?4f0hr@k%gNs2@bO9cPC0>lJi3!W%2n~svM3M95 zge*~Wx2U=**nrtoF=<33rm;|jn6Mid3P^&aBym2HZZMo;3uZI02uwTGLPBm(eK$d5 z<1~%u#R3-+ClTh6Ff!9}8L(ofbD3Xh=&*+&8WPZE!;nUB{Z~BCIg~``>CJ?O6E#mF zKr_NpX?#LH+d?;LqDao7EF?;gBsX?Ew-6lFR5}KbfKLI9U=-tVPcb%(wfdzP;`wu6 zx#!Qfiqy>teL%mlp=QMqrg0BlC_&@ENQRz2S2E}Mb5QH!nB6o%>Y=}~423w+!pgzO zgd&Ay$y6;IdN(P5tsY;p~$H;=YZ`OQ&` z>2#}*7;6h1g8)#IRDHpcjI#KG$SrgXx&-`5WT*_8H;UuVaS|$NY23f)Df{;fa)u^314hAR^4|^R5wi{SUNYF1a zO|EmXu}Hammd|pUs5MkG(m$iOX7i7u7EaSZ>1|W8aUamK^Z&aC<@~?<2QMG}zYp@{ z{-2_20;8CYC-R1vU<3=eXE)Q^B$Cr%rnJ;y%))D%3=bK(S~M$r=uFuT zR`0ONu9D|5nGvYy@&rjI-oThwHpy_FyK6jz^)+P*>xe{MwdiUq6<@#PhlgP++%UZRk(#1b^0fv|b;r*GKDhvGtl( z%`2-Qf_3E?Q!VV;N5l3`hHZiJUz=U~rPZ9rr{Qsn;ombNKz3~Q?*Bh5)Bkt(_jh*7 z`M(c#_8;?qJ;5bfDQwkspcmKhVF}1LCkP?tLA4E2^=zXB0{5t-z zzJ$D+Z(O=Iyej5egmRx2B({PhJFb&l3*hZ3l+R)#<&AVn**Wf)1(nqvu!ILF$Bk>(rX%XV> zS!xNCjm#bYu;GtXuEkfy%hiKxDpwUR#v`uLSX0gvVf;wt{Ro>f!Kz%c)7$AC)UnAW z9zSs3@5Uvepgo;=VNHP(3L01d?O5XI;uP5$_by&kV~4h}cFdxx9P9AW+@xMYxhjVo z^j`ILmN3YdrbHv_tUv-UBzbNA@nE!Pp@A0*{SdVC+uJxJ`Bbd((tht{@1O-QeR+~> zf};`^5na^e=Em!DmVy=NSnz;bXzh9IJ&TA%+adEHq^)mx<9t^~>ni{4^>+7K3A3-0 zUYlS_P6Yk^4kFIfZ_j$?y267H&(Tdcxp6MD#H-V`TXNPHC&wn3$cCrLJ1~+5qdhZS zyI917-Y#Ms#aPMI^{G_mv?_Ug;xygEbH(F)yL_Mv zA^QoZD;76s60RZP**40-4KI^wE}SCZxOb zOVPSg6K+m45rJMm@16KM$l8&9S#XDGv5vSJQVmH>e|p`T2#;1>GyHI*8!-1%L6lxo zt)|!!b94Hl_>jiwD2&3{#GRR_)ksx6WNw~BGQ$S{L;a=z7j{?q^frgPDT`u7u#9Dq9|9Lb56Soz#VVike(; z`H?%bri>^T5=lC>iwOhRIwDoie#Wm69Tj4BCm5pL^V50m9D~QV9(Fe3sXB3&1U(tX zt>`Xw02gt$((JCYA&H4RXG|VbUKo>_u{Wg=XH24qa=89z#TBKE0{5e7N1=s|Z97Xf zwkGes@0~VzHILloZyE=h$Rb1P{S3ILW>^1-Z~JJsPRTVOk)GD(5WeqWUV}jB>95`W zU%Sr?p%(hDx!?Ysh~#-*ACgX<>-2s|<@;tgM=j&Yc}PkbH_ZJ|$@+LUMeFL9OM2g~PR(37s?`M-k=3I24&UZ-$dJ%ZY4i@?(rGqD zd5I#i>~{;yh#$~~4N3IjP%TXIb3H>MZwN`yo+9bqi=A~kZ^b3Z$Gu!W?!DM45=6gP zL<~J-rmn|4m3FHEb`oOV5 zM)#Epgri7HU;iZ9!}7ZMeT*d@U^(#z)Qu#T7`czd(X(YB#i!zJwQMNjK#CDKHacNK zYECaMpH!gk_6+mwm=5!!xZQR7Uu)*pz-~{Aw=BdlmGee=6bjVS#AI2~<$CC_oU8-R zt`-WxO}zS-(-+JdWU81{>C8BN)FK5Oh4s>%vdA%)J~*D&U5BtF$)@m=rQWU60qR=D z@7fnbB4j{DBgSR7G!TB-MdUXNR#n^@Q@@@pJB^Y0F%u@l}3JXR4QL`h`Eo7t87XLn5`jB)XJ|`Kb^9| zrB0R%O)!siYDN^|6o(*8YQ^d9&dxe|XF*vg=?A+z%k%@&k#{tqQyd>!W>`!*QyRJA zi%EB?XW>-U%BCL2!P07}g2-)1NTekp4rPX8lop8IP*I;IhgT+ft1<+&uz=E8B5ACT zQR{pbRG<+jBtltQlm~k+HZ%gpoUN#9?MCCA2*PJ1%BlK>aZiV<8xvc{8wyAV=__<~ zn`{$;xUK4u+ZxhlVJeIRkXlm`_}?WdC`KQ$S)1Fqk-X3O6)0BS#@Z7Z+RkoLuFF+9l4EPv z50)jzb+_6&LmZGqGz4aW89ki!f4@R^<25sUNsR8QF8-2;gJ+}B=y%K6Ev96}dEU)v zUG@{3Nl_NwY?mfsTS3)9%XDw_PLyO%+St7v6z+BArPV&^ zhGVul?)Q*c%_Okfm9`c#5mP=a-oFj^`9i9K@sP_8q}*gxlb?Yr)lE%?W5=4M=$4JA zFMbizRRY#|EF^2;9PWlmz4BFSFju_nYU!W}b8T4GsHL9^_t%Q4 zRt24Q*v>V_Y%gHM1IpOX;`OH*h>Y9|RqMNI#9w2ZyZEXd+Bh0{iB~o^IsC zW?Yt{pmKj_uT#kW1fPN$R4xHcU(2h$YZyVhl&ZlDXenqfg{a&O!1=u1GuF*n38f%k zPx;XYIz4}-b*H>Rh~9rNSHOHgU&1I7IgbsE@hqT3bp!0 zU$EF3fXS#miyhj`X2O(24s)Te*^;YUX5)AS5^bUe*3Gzp8C<8RaWw)`!xy74f69>h zuilOyuzLT(*0w;#>%0ws>Edq#+@P_JtP$Pth=K%ENSByE6<@U!kX;%u7&{6;@W1UH z9T6O>bcLbrtNp$!jQ^r9-te3Eq8190FDJnDfC?WOkxciTWaOa-g}YGhwT83+dJjz7 zMV3#4I1zPLAy`(8)1%pauPggNTk<@-mp1vh*|~1D`Gm#^Vh*VDcv(gv2o)d<)_2PuL885;b@>O|?>D>K}6HxHZ#MwI~jfETx60g;`1k)5+-~PkY+fkWCg6L3>-f z6}e!R=&`pEP51WtZ6lgG7#~A!>xnKL<;yLwACymkS>E;@FB}aHz&?7RV4@2IxMNAX z=2_Mm^*&}bpP4(#B&j6+dd78sE#||tyVnuxb>lRnSq(Ts}JC5P=TWFFkvP9&bKCqet zx#81bs(7c4v?;Vgi)$uoQ(?;3mc3KVw`QUF8iGOD>1{Wu7I3SH!6aHl6d(ajl0X!+ zaR2A-CawFwv=ZAGmR!3X3`>KKVaZ98?-T10-CWXTf)PBpZ1bhS3Ayc>p!^^s>Qrd; zwc|&f*o_*4TkH(H>V;r6DLHs|0yjo2y|y(#+z9ehCrkOKT35Q%^V?CLqx7>@;)j2S z$yDMN;|}~kKKaR7m_T|7s3i%`Hlz^y49ofP_ArRq?iBx5aN=0n%WZH1JQ?n3Y(!sz zdm0-7QV&Xv;Nf_&tm<2bgr}ke4_n0P>?wmSLqoL9`lc*tyP0uGVK!p|h67}>emKv# z&;_`w=6@d$0rc4lB7i{qg9utrRzSpkd{~G;IJ~}A6I~qBlZ@q*Q*bzL#(!m0Z5d?5 zw^Yy2jnHQ_#ijs~Ld<}RB=epdDRMOYGO)7=tAWX?Dcm3_Yr?>;=~!%7$J&qY{i-`5LWFR~H1DtfylX7Ow#8xPlT z*>j|nJ%CGpp!+&LIE2KB%hqjDi4kiFM``XXCHJ2e`W2LVdO4hFGZa@67Ccz@aVTd) zUk7jKRz0NEc6x2m5U#&#NS}t%4sETg$~!|)t80F1htRlv#+#>FZ}V~7@Eb~DPay;a zk}m5mu4glI+Yfkr`d&WrpdgZG@y2I8H&eh=Y3zn0Qs}em`#efTOQuCEk~Xla53CTa zjMPTfw;co7gg&tNrFCc0p6F8t!IeWVhDBFHy{xoy{CkVLtHma+$-_rg}g%SYQgj z)6STofNU63Bx!RGlPacE$iOkaMA1P{gI2Tefx>B3+aH30NsVs%pWtG z!fAmT3eJJuiuw@iGjJPgqxc+p8G3vgv5(K+zdd>T@)V@I!^zkT_FoxM6a zWv4IB&Q9LGWFJq?Ua{wAXU~sby*Oq+zkB`R&5P6hoAahdf?8lpF4}R)LP-mv^G7c0 zKFgkGrL)G&wO(iAJ6i};DqV4?H{vaQiAHImuOSF9G5om`<~0LXF)#zVLpGwZ80Z(+ z@93c#6w$ay!@>QxUT{UhYu@n~jV(^Z^KH?cyAYt8@HA-O>cc;8RNPLrnl{D=<^3bx z3#i&Z5ysu-u6ZD|PmTt9u!*MttCYB11$Gc%QfIcfB=9A4gV&iC^a#fGh#wv`cj&q- z0xdfqcs)mJrD*)8A{?M#NSzr+VZdWKn+ez|P&^~bTN29rAzEL&rw}EF=>O8~-RqS+ zq;L}jR7NCQQ2Z(P1`m7+3c)5rdryM`ZrMxe9`?B8uJvS$S}xCP0I|$nhi8J8E6gzwMtq~WuJqk-Ss~buQ%gd5o8(E9A1`?DD^9mJ! zKiWYMuvb(jGY|Kxj2obqv0V1~09y_hf)~S^o12kb&d&!}zWq@URp3u6KL?uz{tWfX zF=)IL?3!Ej5|g4hfVylT&eQ(!3f9r#D0-$riO?&tKIcTOxAbFsSe6)>JLG_hi7qT; zHkmYK*%dBNkrAZEpgzDnDX#fyc@x_}$_}iM*2h0ry0DQoYo{sCSxSr5)njDlh#f7s znxn$S!BcjobgZH0FX22m*egJ_*IkJ>SL{{QAZJd%A67M$xROG!>X%6f533=#Qv%XTOYYR8B)`;I8{`>w3hcjv4ks^|nEddIp2zw+cF)^McS zh^`l$7Tj4q3+Y=P-l}-y`Zg8bhL=JKs0ry~5LX)$sh___p(o3_-p7(0>bNCnJrC0a z=MY5w7FR*+l9RAXQSVbU-x02<%NH^T+k-Zbq9yj?Hv+GRW&|*pVmp30zvzpHg=OS_ z0+6tN3wg6|!JkDZ2dezy9pUf5q9Nr@9Df1MDCTFZTBtaga%zaH9ZRSTw&z~ICgR?r zZbJ+7V9F2F&*GKoHo9>y_+ayn>Y5xh~SBds{GJbzMHi`C|d`xrq zT{ozkgYE;ZjzEMAl{*)uBQYndB-l#O&jfnh>6u+Go9_V1_r$zy2TR|22VidD3ti}I zRcb8w%KJdc=Ul4j>tkzPH^2mQp9l@1>Ka2uOwSFS4^WYEK499g^FgC7mA+Pc2wvFP z6?)!q!&NOragtZWIhuS(0sbz1qWP1i;70hgd_Uiz>l5Pyy)ACd~BdE_^_^-;W3 zs6*XWY=TKDoWakJG3eOW2um`>t#DX>{N#MFLc#Jgv>LOe;L66TwvZGB77mG^NIz^V zF?Ad5Tc3>zizBV9EQIj`gCZKWW*#)EB%A;;io?=L$3`sAffz&Wyxp zQ5Nic(7oU95rG{QQsFch%F1!p=OmNm-bzT#ibJGzz0mcC&|S1fSIUS0!PwA>s|I-w z5J^$0iEC}#`9Fm6e^t=qw{4%*CmU#NspsGnlhV`Idd}jHxm%3;R=RKWJV}KG`jLp< zR#b)G$)vId2k}zRfjYEVvQ^n6PSi{f(v(Gm30HDDIAnvLc+E@qKQD~Y#{JJnZj}2k zbUI{%V{y^U-T#~!J{5z5eWjs*@wasPBR+r9n0ddapBDsTi#0+~y#PsB|nl$BS4U5F`f ztVokm7(u?#fv3fOb5T>db255tTGL?LB#`ZM45x_YbJv}rHr0Zw=iU(-115ahWB4Wt z)BSR6*}L)y4>0X;lPsU+!dVYo37jU=&xHac^WE)P@m9+j`%7 zBzMdV@DPBfc-6P)k^faEsy}|n!QD-6=QC1x=Y9t&sfPX%0Q_phXEQk+vDboMQTC9F zlB-J}_1eNl-?gD@^iu^!jk5tL08^4;gn1PjpJ{dMl6_-?J=bNjJ!= z#vN`!#d=JmjMl@JJ-IfZRR^D%oM~vP!o6XhaU{=xwo}TksL)BtycP%06JE`aw3e%QXvV}aTcBC2O{ zDRh&h|E3>84mA>(97Uimo&C1E)ICL+kumoE*gg|HC)UIFJRf|2K7h98gQw&3ftSWt z3TfYyXuJc|kb8>|`+hyN{DbZ&?}-zl3@X#x$?SkKrw!J`Z4qsTwD|5)peX9dBe5}2 zU%B8GZ?3miOFu;j$-ei^NR#~R42qNGQWTQcn7IRF0uK{!m59&^jaR`9b9azvaTFa! z60L9!*H;9e0I)={g7*24J!PiN5`+=&Bo5>aQA>t}^+G;Gzmw70!^<5Wq}1^_u*oF= z>2Bii;zxa;E8crj6wta6cj*jVbBw=iWmZ@6W;iuk5h5{wE2U59MkWGTk8(67U;({i zj?GCFXL5#n!0j;`vp;_G9s48u<9eVWN9ciKk0E~QC$|bflrtljUnTBXu5kdNW!Rj> z_KZ4grUTIsA3N7ZE`vi#hj&|YbD63QqOnL7OuF|*O~Dt!y2stKx*#0Zy0YFnmn7B% zheWrgWmDF&Dg~P^WLX&TP_NRA+m`25M{@az+pe=!Y_*vgc5|dsMCy1I#S_HQX1NL_ z*^j6O2C5x28FZ$ofr7#lR^(6~I*cDij1K{~=L38Iyw=w(a|o;0{dKz&2TVY4xO;l5 zrmyO{Ix3}5^-AtQ&)BQ8vkAjyZWI1o+#t-2!cK*`0>_n>gMrFl^)AV9K!eezG&)U6 zmL7BuaWjAlcxUOX%>Xn(lWa@gK#Fg`*9ur%Vg&YrtAMkmLB=FkXUB;H`TD_EnVZl65A z?sU*0cT-FOx8X8?586r)c>lLuV350(W1MXgwBG_qMG?4QxJzL2F#89zJkn(;rtSwn z&j-ur;*F?{oZ7EiUMR73;u~clOJV4+o2nwu+J?h3uC%&c>c$aku%S5)!r@3|bkR&} z$9)-nB`_eVF_pHCTt|6UsKWZu1o6{ERQ~2|=I>G8AsGc5$J(DOi|!iJ#Kc%Lhm`JIkf% zqwyT^2ltrxTl#GEA*2+EtUaVcNnkvkFkTdn`0UPs^*lgOMP(hzT|IUjC`yVEw{nx+ zF0@qm%&cv@U;k!Ww!uB^=}GUNp6p{!*&qqRU2u!Ovq@e&N0x%*b1bezsVlf3f0Z?R zbUHcyD`8YVDrAKN{e=|Qfe{4`5;aVe+6T}{Dt`stVLWu{U?+ZC!z;8&M902Ru$crY)#A&PI z^1thO?cfE~B21%{ujeGy>UoJ*YIg_seMbS%R_ur&q-6kOoT{4o8{O1ZQ?o}W?+#Lj zUew3@qmf3SaTt~8l!a}?o?GyavJf>bK|-)#L471-ya65nuK zKg{J9?0|6cE||y-g^#@}wxn(5iBj7rA$LF7tI8rY&O&v}M*6IINmIGV0M5owg{_6{DpK}Dz(mN^wC zF2zGeG9Km8&eCc}z=k$iaXDeEw6#!E;S-7az{jqu;m-0#njg47Yv|ysPHIyBw)k~) zpqMq-24w!;t=hN|(~`?&a9eNLXmFnQkn1b@wzrcC!VuoaoD}r>N@7A0TN`}9Y)(eg zKxx$L$=Wg;3dk>bdlY${A6yBR^TD)4RL|%Bkm^M)oP%%+C(kj5hA~eEx-hNAu^j-DrxtHxW9pXfceI&9xJU8R zP0;*BU%ZyKFXQC<-9g1(IF^e-y8qGWTKGJ25VLJ4q!PGkdL{h$6*qh-YN+P?=mk0f zJY%2!_Ul0Lr5HRLprU4Q$Oh8BbjLAx=Jx;P@1MvUXa(KwgE$LY-r-=^RRY^U0n+?D z_ru>j;f`m{HWSG`A#j#H=%Mho4~RCdVa3U}m)b_}w|9VKD-03h$695rLWx3F^SRBc zF40S0@R~;)x6hbQYkoN6wqEJmwqL|d9pCSOk(fh0_fH2;;eBFY|C^P$;Xf1#X5do2 z3G%=GF@r`cKr|X`QSQu8!mfiIDixH@p^bDkDISqA-HB!}_-;l5+v9)?-a$#l?`*Eo z8v2?CMTF7;d&1r=55y;`JRr&UMN@48QQaPpzB z3OuPzWA#!Su9mdE=7a^Of2roBu!;BnNgcB;PxW#s6qTj3KD{pWpY@+TIJ1bGN}GB( zGkQ5hoI4+Ef2=9+9PBbUKkQMv?VZBz&Tgx|TX@{w{~gY^|0t=tTb|{(TZlGM9@d&& z3FB`i-lhJrgK8Zn=_y#Kl}NM=@sVjC_rv1mb9~_PVW(Nda0egH2TfIK4gw1n=V;+| z0Yy8mBxfH^vUD$5WsQX}V#GdFK3Xbh9KnW*vkG)BB?W1Ksavj4MH2ZKHb&!Hwv&6@t6ffzQavg8Dk#v&{0HL_yM6G{_IkQcFcL( zKYok5ISFq~j~je?Lz748F8B05bpy{=v~d6B^xa$UJp>~zd6fwiU;lbOXiRxNcy>PU zwlJD?2(u2!19@bh4vm;gtwwywKWoLWEg0%*C(mYG&Iez<{&eu5H}6Nmrrd~GQ+k~N ziCb_l26w^3)}j5z4Cr<)QM-yrF&|xUuYrkp>62D>9HG{Uv#FwmqMcCBLfTaPBdTCF zYh1Q>?%IzohE_e;UQrx+q$elU+&KIbiAz)`y-2Hw`AwxQova>hJD9gYhL); zmxc}f*nNf)4}()-uH;mpZ7JzbIWoP(y48&LkO({!7TUI|Hw`^%Tn3Ieiv-zPL46g^J&Xc0?BjU3hZ zrp8Ua=W4nTW;ikW=C;q80bP+paU>y4#FLQ$3gJ1Sg8FZDAts=0b$_{|@F#)4Wb+b% zSan_DQik!v3+<-}KcusSA3GZiL4WalXqWy5IIJJEZuSr1Hg9?Ndhb%U=5;qJIWk3E zdbp2HNIf-WP!>eR@-Eq_f!y4vG9~vpWqw>H>Gr< zmir?p+8}4)5NvVIP!?)V_;~!}T4bGqRd3b%^A3cN_~fRL$2jBBl-G4B zM%Pjm`r5}z?($x4@>?^F!i1P~)7eLyD%9IacGqq~%emtYDL!mMXpn7cH?;E6YXPIs zeGE@3yec}!C2;iN#-YbEa8>cU15y{Ofx*b21##RnxfLZvE+FF+n>M!AOCNbhDX_t* z`a)pI|4duihD%JaO}kAeJ{AQ=prPw@;SakW>!oC z5pu9`|7g<@P$^FTHe?Ur=iOPOE0iv?QG=^Ry(Z zT+mhp=s$k)r*U6elA({Oql}EuLC@GYW`@jDlR#){Uq%w(A2EQz3+yVS5ApBsWB>eq zKOT=qER943$H6?W!-&0sdcL0Hq{s&&=X3Y0@T9ny&+XtD@fB-4)<8{?GQl|J^+J|0 z+Xpv-*&4GMqc7mLQTbo5;wK(w?8NuucAaZ?KL7Ijzu*7;{_ppHzyJGx_3wWI00960 LR~5?D0K@_SIaIOA literal 0 HcmV?d00001 diff --git a/charts/longhorn/105.0.0+up1.6.3/.helmignore b/charts/longhorn/105.0.0+up1.6.3/.helmignore new file mode 100644 index 0000000000..f0c1319444 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/.helmignore @@ -0,0 +1,21 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj diff --git a/charts/longhorn/105.0.0+up1.6.3/Chart.yaml b/charts/longhorn/105.0.0+up1.6.3/Chart.yaml new file mode 100644 index 0000000000..18c9ae5e47 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/Chart.yaml @@ -0,0 +1,39 @@ +annotations: + catalog.cattle.io/auto-install: longhorn-crd=match + catalog.cattle.io/certified: rancher + catalog.cattle.io/display-name: Longhorn + catalog.cattle.io/kube-version: '>= 1.23.0-0' + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/permits-os: linux,windows + catalog.cattle.io/provides-gvr: longhorn.io/v1beta1 + catalog.cattle.io/rancher-version: '>= 2.10.0-0 < 2.11.0-0' + catalog.cattle.io/release-name: longhorn + catalog.cattle.io/type: cluster-tool + catalog.cattle.io/upstream-version: 1.6.3 +apiVersion: v1 +appVersion: v1.6.3 +description: Longhorn is a distributed block storage system for Kubernetes. +home: https://github.com/longhorn/longhorn +icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/longhorn/icon/color/longhorn-icon-color.png +keywords: +- longhorn +- storage +- distributed +- block +- device +- iscsi +- nfs +maintainers: +- email: maintainers@longhorn.io + name: Longhorn maintainers +name: longhorn +sources: +- https://github.com/longhorn/longhorn +- https://github.com/longhorn/longhorn-engine +- https://github.com/longhorn/longhorn-instance-manager +- https://github.com/longhorn/longhorn-share-manager +- https://github.com/longhorn/longhorn-manager +- https://github.com/longhorn/longhorn-ui +- https://github.com/longhorn/longhorn-tests +- https://github.com/longhorn/backing-image-manager +version: 105.0.0+up1.6.3 diff --git a/charts/longhorn/105.0.0+up1.6.3/README.md b/charts/longhorn/105.0.0+up1.6.3/README.md new file mode 100644 index 0000000000..adb190be3b --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/README.md @@ -0,0 +1,50 @@ +# Longhorn Chart + +> **Important**: Please install the Longhorn chart in the `longhorn-system` namespace only. + +> **Warning**: Longhorn doesn't support downgrading from a higher version to a lower version. + +> **Note**: Use Helm 3 when installing and upgrading Longhorn. Helm 2 is [no longer supported](https://helm.sh/blog/helm-2-becomes-unsupported/). + +## Source Code + +Longhorn is 100% open source software. Project source code is spread across a number of repos: + +1. Longhorn Engine -- Core controller/replica logic https://github.com/longhorn/longhorn-engine +2. Longhorn Instance Manager -- Controller/replica instance lifecycle management https://github.com/longhorn/longhorn-instance-manager +3. Longhorn Share Manager -- NFS provisioner that exposes Longhorn volumes as ReadWriteMany volumes. https://github.com/longhorn/longhorn-share-manager +4. Backing Image Manager -- Backing image file lifecycle management. https://github.com/longhorn/backing-image-manager +5. Longhorn Manager -- Longhorn orchestration, includes CSI driver for Kubernetes https://github.com/longhorn/longhorn-manager +6. Longhorn UI -- Dashboard https://github.com/longhorn/longhorn-ui + +## Prerequisites + +1. A container runtime compatible with Kubernetes (Docker v1.13+, containerd v1.3.7+, etc.) +2. Kubernetes >= v1.21 +3. Make sure `bash`, `curl`, `findmnt`, `grep`, `awk` and `blkid` has been installed in all nodes of the Kubernetes cluster. +4. Make sure `open-iscsi` has been installed, and the `iscsid` daemon is running on all nodes of the Kubernetes cluster. For GKE, recommended Ubuntu as guest OS image since it contains `open-iscsi` already. + +## Upgrading to Kubernetes v1.25+ + +Starting in Kubernetes v1.25, [Pod Security Policies](https://kubernetes.io/docs/concepts/security/pod-security-policy/) have been removed from the Kubernetes API. + +As a result, **before upgrading to Kubernetes v1.25** (or on a fresh install in a Kubernetes v1.25+ cluster), users are expected to perform an in-place upgrade of this chart with `enablePSP` set to `false` if it has been previously set to `true`. + +> **Note:** +> If you upgrade your cluster to Kubernetes v1.25+ before removing PSPs via a `helm upgrade` (even if you manually clean up resources), **it will leave the Helm release in a broken state within the cluster such that further Helm operations will not work (`helm uninstall`, `helm upgrade`, etc.).** +> +> If your charts get stuck in this state, you may have to clean up your Helm release secrets. +Upon setting `enablePSP` to false, the chart will remove any PSP resources deployed on its behalf from the cluster. This is the default setting for this chart. + +As a replacement for PSPs, [Pod Security Admission](https://kubernetes.io/docs/concepts/security/pod-security-admission/) should be used. Please consult the Longhorn docs for more details on how to configure your chart release namespaces to work with the new Pod Security Admission and apply Pod Security Standards. + +## Uninstallation + +To prevent Longhorn from being accidentally uninstalled (which leads to data lost), we introduce a new setting, deleting-confirmation-flag. If this flag is **false**, the Longhorn uninstallation job will fail. Set this flag to **true** to allow Longhorn uninstallation. You can set this flag using setting page in Longhorn UI or `kubectl -n longhorn-system patch -p '{"value": "true"}' --type=merge lhs deleting-confirmation-flag` + +To prevent damage to the Kubernetes cluster, we recommend deleting all Kubernetes workloads using Longhorn volumes (PersistentVolume, PersistentVolumeClaim, StorageClass, Deployment, StatefulSet, DaemonSet, etc). + +From Rancher Cluster Explorer UI, navigate to Apps page, delete app `longhorn` then app `longhorn-crd` in Installed Apps tab. + +--- +Please see [link](https://github.com/longhorn/longhorn) for more information. diff --git a/charts/longhorn/105.0.0+up1.6.3/app-readme.md b/charts/longhorn/105.0.0+up1.6.3/app-readme.md new file mode 100644 index 0000000000..321e5193c4 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/app-readme.md @@ -0,0 +1,27 @@ +# Longhorn + +Longhorn is a lightweight, reliable and easy to use distributed block storage system for Kubernetes. Once deployed, users can leverage persistent volumes provided by Longhorn. + +Longhorn creates a dedicated storage controller for each volume and synchronously replicates the volume across multiple replicas stored on multiple nodes. The storage controller and replicas are themselves orchestrated using Kubernetes. Longhorn supports snapshots, backups and even allows you to schedule recurring snapshots and backups! + +**Important**: Please install Longhorn chart in `longhorn-system` namespace only. + +**Warning**: Longhorn doesn't support downgrading from a higher version to a lower version. + +[Chart Documentation](https://github.com/longhorn/longhorn/blob/master/chart/README.md) + + +## Upgrading to Kubernetes v1.25+ + +Starting in Kubernetes v1.25, [Pod Security Policies](https://kubernetes.io/docs/concepts/security/pod-security-policy/) have been removed from the Kubernetes API. + +As a result, **before upgrading to Kubernetes v1.25** (or on a fresh install in a Kubernetes v1.25+ cluster), users are expected to perform an in-place upgrade of this chart with `enablePSP` set to `false` if it has been previously set to `true`. + +> **Note:** +> If you upgrade your cluster to Kubernetes v1.25+ before removing PSPs via a `helm upgrade` (even if you manually clean up resources), **it will leave the Helm release in a broken state within the cluster such that further Helm operations will not work (`helm uninstall`, `helm upgrade`, etc.).** +> +> If your charts get stuck in this state, please consult the Rancher docs on how to clean up your Helm release secrets. + +Upon setting `enablePSP` to false, the chart will remove any PSP resources deployed on its behalf from the cluster. This is the default setting for this chart. + +As a replacement for PSPs, [Pod Security Admission](https://kubernetes.io/docs/concepts/security/pod-security-admission/) should be used. Please consult the Rancher docs for more details on how to configure your chart release namespaces to work with the new Pod Security Admission and apply Pod Security Standards. \ No newline at end of file diff --git a/charts/longhorn/105.0.0+up1.6.3/questions.yaml b/charts/longhorn/105.0.0+up1.6.3/questions.yaml new file mode 100644 index 0000000000..1742ce69eb --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/questions.yaml @@ -0,0 +1,920 @@ +categories: +- storage +namespace: longhorn-system +questions: +- variable: image.defaultImage + default: "true" + description: "Use default Longhorn images" + label: Use Default Images + type: boolean + show_subquestion_if: false + group: "Longhorn Images" + subquestions: + - variable: image.longhorn.manager.repository + default: rancher/mirrored-longhornio-longhorn-manager + description: "Repository for the Longhorn Manager image." + type: string + label: Longhorn Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.manager.tag + default: v1.6.3 + description: "Specify Longhorn Manager Image Tag" + type: string + label: Longhorn Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.engine.repository + default: rancher/mirrored-longhornio-longhorn-engine + description: "Repository for the Longhorn Engine image." + type: string + label: Longhorn Engine Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.engine.tag + default: v1.6.3 + description: "Specify Longhorn Engine Image Tag" + type: string + label: Longhorn Engine Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.ui.repository + default: rancher/mirrored-longhornio-longhorn-ui + description: "Repository for the Longhorn UI image." + type: string + label: Longhorn UI Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.ui.tag + default: v1.6.3 + description: "Specify Longhorn UI Image Tag" + type: string + label: Longhorn UI Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.instanceManager.repository + default: rancher/mirrored-longhornio-longhorn-instance-manager + description: "Repository for the Longhorn Instance Manager image." + type: string + label: Longhorn Instance Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.instanceManager.tag + default: v1.6.3 + description: "Specify Longhorn Instance Manager Image Tag" + type: string + label: Longhorn Instance Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.shareManager.repository + default: rancher/mirrored-longhornio-longhorn-share-manager + description: "Repository for the Longhorn Share Manager image." + type: string + label: Longhorn Share Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.shareManager.tag + default: v1.6.3 + description: "Specify Longhorn Share Manager Image Tag" + type: string + label: Longhorn Share Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.backingImageManager.repository + default: rancher/mirrored-longhornio-backing-image-manager + description: "Repository for the Backing Image Manager image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn Backing Image Manager Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.backingImageManager.tag + default: v1.6.3 + description: "Specify Longhorn Backing Image Manager Image Tag" + type: string + label: Longhorn Backing Image Manager Image Tag + group: "Longhorn Images Settings" + - variable: image.longhorn.supportBundleKit.repository + default: rancher/mirrored-longhornio-support-bundle-kit + description: "Repository for the Longhorn Support Bundle Manager image." + type: string + label: Longhorn Support Bundle Kit Image Repository + group: "Longhorn Images Settings" + - variable: image.longhorn.supportBundleKit.tag + default: v0.0.43 + description: "Tag for the Longhorn Support Bundle Manager image." + type: string + label: Longhorn Support Bundle Kit Image Tag + group: "Longhorn Images Settings" + - variable: image.csi.attacher.repository + default: rancher/mirrored-longhornio-csi-attacher + description: "Repository for the CSI attacher image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Attacher Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.attacher.tag + default: v4.7.0 + description: "Tag for the CSI attacher image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Attacher Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.provisioner.repository + default: rancher/mirrored-longhornio-csi-provisioner + description: "Repository for the CSI Provisioner image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Provisioner Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.provisioner.tag + default: v3.6.4 + description: "Tag for the CSI Provisioner image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Provisioner Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.nodeDriverRegistrar.repository + default: rancher/mirrored-longhornio-csi-node-driver-registrar + description: "Repository for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Node Driver Registrar Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.nodeDriverRegistrar.tag + default: v2.12.0 + description: "Tag for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Node Driver Registrar Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.resizer.repository + default: rancher/mirrored-longhornio-csi-resizer + description: "Repository for the CSI Resizer image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Resizer Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.resizer.tag + default: v1.12.0 + description: "Tag for the CSI Resizer image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Resizer Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.snapshotter.repository + default: rancher/mirrored-longhornio-csi-snapshotter + description: "Repository for the CSI Snapshotter image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Snapshotter Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.snapshotter.tag + default: v6.3.4 + description: "Tag for the CSI Snapshotter image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Driver Snapshotter Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.csi.livenessProbe.repository + default: rancher/mirrored-longhornio-livenessprobe + description: "Repository for the CSI liveness probe image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Liveness Probe Image Repository + group: "Longhorn CSI Driver Images" + - variable: image.csi.livenessProbe.tag + default: v2.14.0 + description: "Tag for the CSI liveness probe image. When unspecified, Longhorn uses the default value." + type: string + label: Longhorn CSI Liveness Probe Image Tag + group: "Longhorn CSI Driver Images" + - variable: image.openshift.oauthProxy.repository + default: rancher/mirrored-longhornio-openshift-origin-oauth-proxy + description: "Repository for the OAuth Proxy image. This setting applies only to OpenShift users" + type: string + label: OpenShift OAuth Proxy Image Repository + group: "OpenShift Images" + - variable: image.openshift.oauthProxy.tag + default: 4.15 + description: "Tag for the OAuth Proxy image. This setting applies only to OpenShift users. Specify OCP/OKD version 4.1 or later." + type: string + label: OpenShift OAuth Proxy Image Tag + group: "OpenShift Images" +- variable: privateRegistry.registryUrl + label: Private registry URL + description: "URL of a private registry. When unspecified, Longhorn uses the default system registry." + group: "Private Registry Settings" + type: string + default: "" +- variable: privateRegistry.registrySecret + label: Private registry secret name + description: "Kubernetes secret that allows you to pull images from a private registry. This setting applies only when creation of private registry secrets is enabled. You must include the private registry name in the secret name." + group: "Private Registry Settings" + type: string + default: "" +- variable: privateRegistry.createSecret + default: "true" + description: "Setting that allows you to create a private registry secret." + type: boolean + group: "Private Registry Settings" + label: Create Secret for Private Registry Settings + show_subquestion_if: true + subquestions: + - variable: privateRegistry.registryUser + label: Private registry user + description: "User account used for authenticating with a private registry." + type: string + default: "" + - variable: privateRegistry.registryPasswd + label: Private registry password + description: "Password for authenticating with a private registry." + type: password + default: "" +- variable: longhorn.default_setting + default: "false" + description: "Customize the default settings before installing Longhorn for the first time. This option will only work if the cluster hasn't installed Longhorn." + label: "Customize Default Settings" + type: boolean + show_subquestion_if: true + group: "Longhorn Default Settings" + subquestions: + - variable: csi.kubeletRootDir + default: + description: "kubelet root directory. When unspecified, Longhorn uses the default value." + type: string + label: Kubelet Root Directory + group: "Longhorn CSI Driver Settings" + - variable: csi.attacherReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Attacher. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Attacher replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.provisionerReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Provisioner. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Provisioner replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.resizerReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Resizer. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Resizer replica count + group: "Longhorn CSI Driver Settings" + - variable: csi.snapshotterReplicaCount + type: int + default: 3 + min: 1 + max: 10 + description: "Replica count of the CSI Snapshotter. When unspecified, Longhorn uses the default value (\"3\")." + label: Longhorn CSI Snapshotter replica count + group: "Longhorn CSI Driver Settings" + - variable: defaultSettings.backupTarget + label: Backup Target + description: "Endpoint used to access the backupstore. (Options: \"NFS\", \"CIFS\", \"AWS\", \"GCP\", \"AZURE\")" + group: "Longhorn Default Settings" + type: string + default: + - variable: defaultSettings.backupTargetCredentialSecret + label: Backup Target Credential Secret + description: "Name of the Kubernetes secret associated with the backup target." + group: "Longhorn Default Settings" + type: string + default: + - variable: defaultSettings.allowRecurringJobWhileVolumeDetached + label: Allow Recurring Job While Volume Is Detached + description: 'Setting that allows Longhorn to automatically attach a volume and create snapshots or backups when recurring jobs are run.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.snapshotMaxCount + label: Snapshot Maximum Count + description: 'Maximum snapshot count for a volume. The value should be between 2 to 250.' + group: "Longhorn Default Settings" + type: int + min: 2 + max: 250 + default: 250 + - variable: defaultSettings.createDefaultDiskLabeledNodes + label: Create Default Disk on Labeled Nodes + description: 'Setting that allows Longhorn to automatically create a default disk only on nodes with the label "node.longhorn.io/create-default-disk=true" (if no other disks exist). When this setting is disabled, Longhorn creates a default disk on each node that is added to the cluster.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.defaultDataPath + label: Default Data Path + description: 'Default path for storing data on a host. The default value is "/var/lib/longhorn/".' + group: "Longhorn Default Settings" + type: string + default: "/var/lib/longhorn/" + - variable: defaultSettings.defaultDataLocality + label: Default Data Locality + description: 'Default data locality. A Longhorn volume has data locality if a local replica of the volume exists on the same node as the pod that is using the volume.' + group: "Longhorn Default Settings" + type: enum + options: + - "disabled" + - "best-effort" + default: "disabled" + - variable: defaultSettings.replicaSoftAntiAffinity + label: Replica Node Level Soft Anti-Affinity + description: 'Allow scheduling on nodes with existing healthy replicas of the same volume. By default, false.' + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.replicaAutoBalance + label: Replica Auto Balance + description: 'Enable this setting automatically re-balances replicas when discovered an available node.' + group: "Longhorn Default Settings" + type: enum + options: + - "disabled" + - "least-effort" + - "best-effort" + default: "disabled" + - variable: defaultSettings.storageOverProvisioningPercentage + label: Storage Over Provisioning Percentage + description: "Percentage of storage that can be allocated relative to hard drive capacity. The default value is 100." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 100 + - variable: defaultSettings.storageMinimalAvailablePercentage + label: Storage Minimal Available Percentage + description: "If the minimum available disk capacity exceeds the actual percentage of available disk capacity, the disk becomes unschedulable until more space is freed up. By default, 25." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 100 + default: 25 + - variable: defaultSettings.storageReservedPercentageForDefaultDisk + label: Storage Reserved Percentage For Default Disk + description: "The reserved percentage specifies the percentage of disk space that will not be allocated to the default disk on each new Longhorn node." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 100 + default: 30 + - variable: defaultSettings.upgradeChecker + label: Enable Upgrade Checker + description: 'Upgrade Checker that periodically checks for new Longhorn versions. When a new version is available, a notification appears on the Longhorn UI. This setting is enabled by default.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.defaultReplicaCount + label: Default Replica Count + description: "Default number of replicas for volumes created using the Longhorn UI. For Kubernetes configuration, modify the `numberOfReplicas` field in the StorageClass. The default value is \"3\"." + group: "Longhorn Default Settings" + type: int + min: 1 + max: 20 + default: 3 + - variable: defaultSettings.defaultLonghornStaticStorageClass + label: Default Longhorn Static StorageClass Name + description: "Default Longhorn StorageClass. \"storageClassName\" is assigned to PVs and PVCs that are created for an existing Longhorn volume. \"storageClassName\" can also be used as a label, so it is possible to use a Longhorn StorageClass to bind a workload to an existing PV without creating a Kubernetes StorageClass object. The default value is \"longhorn-static\"." + group: "Longhorn Default Settings" + type: string + default: "longhorn-static" + - variable: defaultSettings.backupstorePollInterval + label: Backupstore Poll Interval + description: "Number of seconds that Longhorn waits before checking the backupstore for new backups. The default value is \"300\". When the value is \"0\", polling is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 300 + - variable: defaultSettings.failedBackupTTL + label: Failed Backup Time to Live + description: "Number of minutes that Longhorn keeps a failed backup resource. When the value is \"0\", automatic deletion is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1440 + - variable: defaultSettings.restoreVolumeRecurringJobs + label: Restore Volume Recurring Jobs + description: "Restore recurring jobs from the backup volume on the backup target and create recurring jobs if not exist during a backup restoration." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.recurringSuccessfulJobsHistoryLimit + label: Cronjob Successful Jobs History Limit + description: "This setting specifies how many successful backup or snapshot job histories should be retained. History will not be retained if the value is 0." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.recurringFailedJobsHistoryLimit + label: Cronjob Failed Jobs History Limit + description: 'Maximum number of failed recurring backup and snapshot jobs to be retained. When the value is "0", a history of failed recurring jobs is not retained.' + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.recurringJobMaxRetention + label: Maximum Retention Number for Recurring Job + description: "Maximum number of snapshots or backups to be retained." + group: "Longhorn Default Settings" + type: int + default: 100 + - variable: defaultSettings.supportBundleFailedHistoryLimit + label: SupportBundle Failed History Limit + description: "This setting specifies how many failed support bundles can exist in the cluster. Set this value to **0** to have Longhorn automatically purge all failed support bundles." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 1 + - variable: defaultSettings.autoSalvage + label: Automatic salvage + description: "Setting that allows Longhorn to automatically salvage volumes when all replicas become faulty (for example, when the network connection is interrupted). Longhorn determines which replicas are usable and then uses these replicas for the volume. This setting is enabled by default." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly + label: Automatically Delete Workload Pod when The Volume Is Detached Unexpectedly + description: 'Setting that allows Longhorn to automatically delete a workload pod that is managed by a controller (for example, daemonset) whenever a Longhorn volume is detached unexpectedly (for example, during Kubernetes upgrades). After deletion, the controller restarts the pod and then Kubernetes handles volume reattachment and remounting.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.disableSchedulingOnCordonedNode + label: Disable Scheduling On Cordoned Node + description: "Setting that prevents Longhorn Manager from scheduling replicas on a cordoned Kubernetes node. This setting is enabled by default." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.replicaZoneSoftAntiAffinity + label: Replica Zone Level Soft Anti-Affinity + description: "Allow scheduling new Replicas of Volume to the Nodes in the same Zone as existing healthy Replicas. Nodes don't belong to any Zone will be treated as in the same Zone. Notice that Longhorn relies on label `topology.kubernetes.io/zone=` in the Kubernetes node object to identify the zone. By, default true." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.replicaDiskSoftAntiAffinity + label: Replica Disk Level Soft Anti-Affinity + description: 'Allow scheduling on disks with existing healthy replicas of the same volume. By default, true.' + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.allowEmptyNodeSelectorVolume + label: Allow Empty Node Selector Volume + description: "Setting that allows scheduling of empty node selector volumes to any node." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.allowEmptyDiskSelectorVolume + label: Allow Empty Disk Selector Volume + description: "Setting that allows scheduling of empty disk selector volumes to any disk." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.nodeDownPodDeletionPolicy + label: Pod Deletion Policy When Node is Down + description: "Policy that defines the action Longhorn takes when a volume is stuck with a StatefulSet or Deployment pod on a node that failed." + group: "Longhorn Default Settings" + type: enum + options: + - "do-nothing" + - "delete-statefulset-pod" + - "delete-deployment-pod" + - "delete-both-statefulset-and-deployment-pod" + default: "do-nothing" + - variable: defaultSettings.nodeDrainPolicy + label: Node Drain Policy + description: "Policy that defines the action Longhorn takes when a node with the last healthy replica of a volume is drained." + group: "Longhorn Default Settings" + type: enum + options: + - "block-for-eviction" + - "block-for-eviction-if-contains-last-replica" + - "block-if-contains-last-replica" + - "allow-if-replica-is-stopped" + - "always-allow" + default: "block-if-contains-last-replica" + - variable: defaultSettings.detachManuallyAttachedVolumesWhenCordoned + label: Detach Manually Attached Volumes When Cordoned + description: "Setting that allows automatic detaching of manually-attached volumes when a node is cordoned." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.priorityClass + label: Priority Class + description: "PriorityClass for system-managed Longhorn components. This setting can help prevent Longhorn components from being evicted under Node Pressure. Longhorn system contains user deployed components (E.g, Longhorn manager, Longhorn driver, Longhorn UI) and system managed components (E.g, instance manager, engine image, CSI driver, etc.) Note that this will be applied to Longhorn user-deployed components by default if there are no priority class values set yet, such as `longhornManager.priorityClass`. WARNING: DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES." + group: "Longhorn Default Settings" + type: string + default: "longhorn-critical" + - variable: defaultSettings.replicaReplenishmentWaitInterval + label: Replica Replenishment Wait Interval + description: "The interval in seconds determines how long Longhorn will at least wait to reuse the existing data on a failed replica rather than directly creating a new replica for a degraded volume." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 600 + - variable: defaultSettings.concurrentReplicaRebuildPerNodeLimit + label: Concurrent Replica Rebuild Per Node Limit + description: "Maximum number of replicas that can be concurrently rebuilt on each node. + WARNING: + - The old setting \"Disable Replica Rebuild\" is replaced by this setting. + - Different from relying on replica starting delay to limit the concurrent rebuilding, if the rebuilding is disabled, replica object replenishment will be directly skipped. + - When the value is 0, the eviction and data locality feature won't work. But this shouldn't have any impact to any current replica rebuild and backup restore." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 5 + - variable: defaultSettings.concurrentVolumeBackupRestorePerNodeLimit + label: Concurrent Volume Backup Restore Per Node Limit + description: "Maximum number of volumes that can be concurrently restored on each node using a backup. When the value is \"0\", restoration of volumes using a backup is disabled." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 5 + - variable: defaultSettings.disableRevisionCounter + label: Disable Revision Counter + description: "Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the \"volume-head-xxx.img\" file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. This setting applies only to volumes created using the Longhorn UI." + group: "Longhorn Default Settings" + type: boolean + default: "false" + - variable: defaultSettings.systemManagedPodsImagePullPolicy + label: System Managed Pod Image Pull Policy + description: "Image pull policy for system-managed pods, such as Instance Manager, engine images, and CSI Driver. Changes to the image pull policy are applied only after the system-managed pods restart." + group: "Longhorn Default Settings" + type: enum + options: + - "if-not-present" + - "always" + - "never" + default: "if-not-present" + - variable: defaultSettings.allowVolumeCreationWithDegradedAvailability + label: Allow Volume Creation with Degraded Availability + description: "Setting that allows you to create and attach a volume without having all replicas scheduled at the time of creation." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoCleanupSystemGeneratedSnapshot + label: Automatically Cleanup System Generated Snapshot + description: "Setting that allows Longhorn to automatically clean up the system-generated snapshot after replica rebuilding is completed." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.autoCleanupRecurringJobBackupSnapshot + label: Automatically Cleanup Recurring Job Backup Snapshot + description: "Setting that allows Longhorn to automatically clean up the snapshot generated by a recurring backup job." + group: "Longhorn Default Settings" + type: boolean + default: "true" + - variable: defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit + label: Concurrent Automatic Engine Upgrade Per Node Limit + description: "Maximum number of engines that are allowed to concurrently upgrade on each node after Longhorn Manager is upgraded. When the value is \"0\", Longhorn does not automatically upgrade volume engines to the new default engine image version." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 0 + - variable: defaultSettings.backingImageCleanupWaitInterval + label: Backing Image Cleanup Wait Interval + description: "Number of minutes that Longhorn waits before cleaning up the backing image file when no replicas in the disk are using it." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 60 + - variable: defaultSettings.backingImageRecoveryWaitInterval + label: Backing Image Recovery Wait Interval + description: "Number of seconds that Longhorn waits before downloading a backing image file again when the status of all image disk files changes to \"failed\" or \"unknown\"." + group: "Longhorn Default Settings" + type: int + min: 0 + default: 300 + - variable: defaultSettings.guaranteedInstanceManagerCPU + label: Guaranteed Instance Manager CPU + description: "Percentage of the total allocatable CPU resources on each node to be reserved for each instance manager pod when the V1 Data Engine is enabled. The default value is \"12\". + WARNING: + - Value 0 means removing the CPU requests from spec of instance manager pods. + - Considering the possible number of new instance manager pods in a further system upgrade, this integer value ranges from 0 to 40. + - One more set of instance manager pods may need to be deployed when the Longhorn system is upgraded. If current available CPUs of the nodes are not enough for the new instance manager pods, you need to detach the volumes using the oldest instance manager pods so that Longhorn can clean up the old pods automatically and release the CPU resources. And the new pods with the latest instance manager image will be launched then. + - This global setting will be ignored for a node if the field \"InstanceManagerCPURequest\" on the node is set. + - After this setting is changed, all instance manager pods using this global setting on all the nodes will be automatically restarted. In other words, DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES." + group: "Longhorn Default Settings" + type: int + min: 0 + max: 40 + default: 12 + - variable: defaultSettings.logLevel + label: Log Level + description: 'Log levels that indicate the type and severity of logs in Longhorn Manager. The default value is "Info". (Options: "Panic", "Fatal", "Error", "Warn", "Info", "Debug", "Trace")' + group: "Longhorn Default Settings" + type: string + default: "Info" + - variable: defaultSettings.disableSnapshotPurge + label: Disable Snapshot Purge + description: "Setting that temporarily prevents all attempts to purge volume snapshots." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.kubernetesClusterAutoscalerEnabled + label: Kubernetes Cluster Autoscaler Enabled (Experimental) + description: "Setting that notifies Longhorn that the cluster is using the Kubernetes Cluster Autoscaler. + WARNING: + - Replica rebuilding could be expensive because nodes with reusable replicas could get removed by the Kubernetes Cluster Autoscaler." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.orphanAutoDeletion + label: Orphaned Data Cleanup + description: "Setting that allows Longhorn to automatically delete an orphaned resource and the corresponding data (for example, stale replicas). Orphaned resources on failed or unknown nodes are not automatically cleaned up." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.storageNetwork + label: Storage Network + description: "Longhorn uses the storage network for in-cluster data traffic. Leave this blank to use the Kubernetes cluster network. + WARNING: + - This setting should change after detaching all Longhorn volumes, as some of the Longhorn system component pods will get recreated to apply the setting. Longhorn will try to block this setting update when there are attached volumes." + group: "Longhorn Default Settings" + type: string + default: +- variable: defaultSettings.deletingConfirmationFlag + label: Deleting Confirmation Flag + description: "Flag that prevents accidental uninstallation of Longhorn." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.engineReplicaTimeout + label: Timeout between Engine and Replica + description: "Timeout between the Longhorn Engine and replicas. Specify a value between \"8\" and \"30\" seconds. The default value is \"8\"." + group: "Longhorn Default Settings" + type: int + default: "8" +- variable: defaultSettings.snapshotDataIntegrity + label: Snapshot Data Integrity + description: "This setting allows users to enable or disable snapshot hashing and data integrity checking." + group: "Longhorn Default Settings" + type: string + default: "disabled" +- variable: defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation + label: Immediate Snapshot Data Integrity Check After Creating a Snapshot + description: "Hashing snapshot disk files impacts the performance of the system. The immediate snapshot hashing and checking can be disabled to minimize the impact after creating a snapshot." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.snapshotDataIntegrityCronjob + label: Snapshot Data Integrity Check CronJob + description: "Unix-cron string format. The setting specifies when Longhorn checks the data integrity of snapshot disk files." + group: "Longhorn Default Settings" + type: string + default: "0 0 */7 * *" +- variable: defaultSettings.removeSnapshotsDuringFilesystemTrim + label: Remove Snapshots During Filesystem Trim + description: "This setting allows Longhorn filesystem trim feature to automatically mark the latest snapshot and its ancestors as removed and stops at the snapshot containing multiple children." + group: "Longhorn Default Settings" + type: boolean + default: "false" +- variable: defaultSettings.fastReplicaRebuildEnabled + label: Fast Replica Rebuild Enabled + description: "Setting that allows fast rebuilding of replicas using the checksum of snapshot disk files. Before enabling this setting, you must set the snapshot-data-integrity value to \"enable\" or \"fast-check\"." + group: "Longhorn Default Settings" + type: boolean + default: false +- variable: defaultSettings.replicaFileSyncHttpClientTimeout + label: Timeout of HTTP Client to Replica File Sync Server + description: "In seconds. The setting specifies the HTTP client timeout to the file sync server." + group: "Longhorn Default Settings" + type: int + default: "30" +- variable: defaultSettings.backupCompressionMethod + label: Backup Compression Method + description: "Setting that allows you to specify a backup compression method." + group: "Longhorn Default Settings" + type: string + default: "lz4" +- variable: defaultSettings.backupConcurrentLimit + label: Backup Concurrent Limit Per Backup + description: "Maximum number of worker threads that can concurrently run for each backup." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 2 +- variable: defaultSettings.restoreConcurrentLimit + label: Restore Concurrent Limit Per Backup + description: "This setting controls how many worker threads per restore concurrently." + group: "Longhorn Default Settings" + type: int + min: 1 + default: 2 +- variable: defaultSettings.allowCollectingLonghornUsageMetrics + label: Allow Collecting Longhorn Usage Metrics + description: "Setting that allows Longhorn to periodically collect anonymous usage data for product improvement purposes. Longhorn sends collected data to the [Upgrade Responder](https://github.com/longhorn/upgrade-responder) server, which is the data source of the Longhorn Public Metrics Dashboard (https://metrics.longhorn.io). The Upgrade Responder server does not store data that can be used to identify clients, including IP addresses." + group: "Longhorn Default Settings" + type: boolean + default: true +- variable: defaultSettings.v1DataEngine + label: V1 Data Engine + description: "Setting that allows you to enable the V1 Data Engine." + group: "Longhorn V1 Data Engine Settings" + type: boolean + default: true +- variable: defaultSettings.v2DataEngine + label: V2 Data Engine + description: "Setting that allows you to enable the V2 Data Engine, which is based on the Storage Performance Development Kit (SPDK). The V2 Data Engine is a preview feature and should not be used in production environments. + WARNING: + - DO NOT CHANGE THIS SETTING WITH ATTACHED VOLUMES. Longhorn will block this setting update when there are attached volumes. + - When the V2 Data Engine is enabled, each instance-manager pod utilizes 1 CPU core. This high CPU usage is attributed to the spdk_tgt process running within each instance-manager pod. The spdk_tgt process is responsible for handling input/output (IO) operations and requires intensive polling. As a result, it consumes 100% of a dedicated CPU core to efficiently manage and process the IO requests, ensuring optimal performance and responsiveness for storage operations." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: boolean + default: false +- variable: defaultSettings.v2DataEngineHugepageLimit + label: V2 Data Engine + description: "This allows users to configure maximum huge page size (in MiB) for the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + type: int + default: "2048" +- variable: defaultSettings.offlineReplicaRebuilding + label: Offline Replica Rebuilding + description: "Setting that allows rebuilding of offline replicas for volumes using the V2 Data Engine." + group: "Longhorn V2 Data Engine (Preview Feature) Settings" + required: true + type: enum + options: + - "enabled" + - "disabled" + default: "enabled" +- variable: persistence.defaultClass + default: "true" + description: "Setting that allows you to specify the default Longhorn StorageClass." + label: Default Storage Class + group: "Longhorn Storage Class Settings" + required: true + type: boolean +- variable: persistence.reclaimPolicy + label: Storage Class Retain Policy + description: "Reclaim policy that provides instructions for handling of a volume after its claim is released. (Options: \"Retain\", \"Delete\")" + group: "Longhorn Storage Class Settings" + required: true + type: enum + options: + - "Delete" + - "Retain" + default: "Delete" +- variable: persistence.defaultClassReplicaCount + description: "Replica count of the default Longhorn StorageClass." + label: Default Storage Class Replica Count + group: "Longhorn Storage Class Settings" + type: int + min: 1 + max: 10 + default: 3 +- variable: persistence.defaultDataLocality + description: "Data locality of the default Longhorn StorageClass. (Options: \"disabled\", \"best-effort\")" + label: Default Storage Class Data Locality + group: "Longhorn Storage Class Settings" + type: enum + options: + - "disabled" + - "best-effort" + default: "disabled" +- variable: persistence.recurringJobSelector.enable + description: "Setting that allows you to enable the recurring job selector for a Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Recurring Job Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.recurringJobSelector.jobList + description: 'Recurring job selector for a Longhorn StorageClass. Ensure that quotes are used correctly when specifying job parameters. (Example: `[{"name":"backup", "isGroup":true}]`)' + label: Storage Class Recurring Job Selector List + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.defaultNodeSelector.enable + description: "Setting that allows you to enable the node selector for the default Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Enable Storage Class Node Selector + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.defaultNodeSelector.selector + label: Storage Class Node Selector + description: 'Node selector for the default Longhorn StorageClass. Longhorn uses only nodes with the specified tags for storing volume data. (Examples: "storage,fast")' + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.backingImage.enable + description: "Setting that allows you to use a backing image in a Longhorn StorageClass." + group: "Longhorn Storage Class Settings" + label: Default Storage Class Backing Image + type: boolean + default: false + show_subquestion_if: true + subquestions: + - variable: persistence.backingImage.name + description: 'Backing image to be used for creating and restoring volumes in a Longhorn StorageClass. When no backing images are available, specify the data source type and parameters that Longhorn can use to create a backing image.' + label: Storage Class Backing Image Name + group: "Longhorn Storage Class Settings" + type: string + default: + - variable: persistence.backingImage.expectedChecksum + description: 'Expected SHA-512 checksum of a backing image used in a Longhorn StorageClass. + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - It is not recommended to set this field if the data source type is \"export-from-volume\".' + label: Storage Class Backing Image Expected SHA512 Checksum + group: "Longhorn Storage Class Settings" + type: string + default: + - variable: persistence.backingImage.dataSourceType + description: 'Data source type of a backing image used in a Longhorn StorageClass. If the backing image exists in the cluster, Longhorn uses this setting to verify the image. If the backing image does not exist, Longhorn creates one using the specified data source type. + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - As for backing image creation with data source type \"upload\", it is recommended to do it via UI rather than StorageClass here. Uploading requires file data sending to the Longhorn backend after the object creation, which is complicated if you want to handle it manually.' + label: Storage Class Backing Image Data Source Type + group: "Longhorn Storage Class Settings" + type: enum + options: + - "" + - "download" + - "upload" + - "export-from-volume" + default: "" + - variable: persistence.backingImage.dataSourceParameters + description: "Data source parameters of a backing image used in a Longhorn StorageClass. You can specify a JSON string of a map. (Example: `'{\"url\":\"https://backing-image-example.s3-region.amazonaws.com/test-backing-image\"}'`) + WARNING: + - If the backing image name is not specified, setting this field is meaningless. + - Be careful of the quotes here." + label: Storage Class Backing Image Data Source Parameters + group: "Longhorn Storage Class Settings" + type: string + default: +- variable: persistence.removeSnapshotsDuringFilesystemTrim + description: "Setting that allows you to enable automatic snapshot removal during filesystem trim for a Longhorn StorageClass. (Options: \"ignored\", \"enabled\", \"disabled\")" + label: Default Storage Class Remove Snapshots During Filesystem Trim + group: "Longhorn Storage Class Settings" + type: enum + options: + - "ignored" + - "enabled" + - "disabled" + default: "ignored" +- variable: ingress.enabled + default: "false" + description: "Expose app using Layer 7 Load Balancer - ingress" + type: boolean + group: "Services and Load Balancing" + label: Expose app using Layer 7 Load Balancer + show_subquestion_if: true + subquestions: + - variable: ingress.host + default: "xip.io" + description: "Hostname of the Layer 7 load balancer." + type: hostname + required: true + label: Layer 7 Load Balancer Hostname + - variable: ingress.path + default: "/" + description: "Default ingress path. You can access the Longhorn UI by following the full ingress path {{host}}+{{path}}." + type: string + required: true + label: Ingress Path +- variable: service.ui.type + default: "Rancher-Proxy" + description: "Service type for Longhorn UI. (Options: \"ClusterIP\", \"NodePort\", \"LoadBalancer\", \"Rancher-Proxy\")" + type: enum + options: + - "ClusterIP" + - "NodePort" + - "LoadBalancer" + - "Rancher-Proxy" + label: Longhorn UI Service + show_if: "ingress.enabled=false" + group: "Services and Load Balancing" + show_subquestion_if: "NodePort" + subquestions: + - variable: service.ui.nodePort + default: "" + description: "NodePort port number for Longhorn UI. When unspecified, Longhorn selects a free port between 30000 and 32767." + type: int + min: 30000 + max: 32767 + show_if: "service.ui.type=NodePort||service.ui.type=LoadBalancer" + label: UI Service NodePort number +- variable: enablePSP + default: "false" + description: "Setting that allows you to enable pod security policies (PSPs) that allow privileged Longhorn pods to start. This setting applies only to clusters running Kubernetes 1.25 and earlier, and with the built-in Pod Security admission controller enabled." + label: Pod Security Policy + type: boolean + group: "Other Settings" +- variable: global.cattle.windowsCluster.enabled + default: "false" + description: "Setting that allows Longhorn to run on a Rancher Windows cluster." + label: Rancher Windows Cluster + type: boolean + group: "Other Settings" +- variable: networkPolicies.enabled + description: "Setting that allows you to enable network policies that control access to Longhorn pods. + Warning: The Rancher Proxy will not work if this feature is enabled and a custom NetworkPolicy must be added." + group: "Other Settings" + label: Network Policies + default: "false" + type: boolean + subquestions: + - variable: networkPolicies.type + label: Network Policies for Ingress + description: "Distribution that determines the policy for allowing access for an ingress. (Options: \"k3s\", \"rke2\", \"rke1\")" + show_if: "networkPolicies.enabled=true&&ingress.enabled=true" + type: enum + default: "rke2" + options: + - "rke1" + - "rke2" + - "k3s" + - variable: defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU + label: Guaranteed Instance Manager CPU for V2 Data Engine + description: 'Number of millicpus on each node to be reserved for each Instance Manager pod when the V2 Data Engine is enabled. The default value is "1250". + WARNING: + - Specifying a value of 0 disables CPU requests for instance manager pods. You must specify an integer between 1000 and 8000. + - This is a global setting. Modifying the value triggers an automatic restart of the instance manager pods. Do not modify the value while volumes are still attached." + group: "Longhorn Default Settings' + type: int + min: 1000 + max: 8000 + default: 1250 \ No newline at end of file diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/NOTES.txt b/charts/longhorn/105.0.0+up1.6.3/templates/NOTES.txt new file mode 100644 index 0000000000..cca7cd77b9 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/NOTES.txt @@ -0,0 +1,5 @@ +Longhorn is now installed on the cluster! + +Please wait a few minutes for other Longhorn components such as CSI deployments, Engine Images, and Instance Managers to be initialized. + +Visit our documentation at https://longhorn.io/docs/ diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/_helpers.tpl b/charts/longhorn/105.0.0+up1.6.3/templates/_helpers.tpl new file mode 100644 index 0000000000..3fbc2ac02f --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/_helpers.tpl @@ -0,0 +1,66 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "longhorn.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +*/}} +{{- define "longhorn.fullname" -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "longhorn.managerIP" -}} +{{- $fullname := (include "longhorn.fullname" .) -}} +{{- printf "http://%s-backend:9500" $fullname | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "secret" }} +{{- printf "{\"auths\": {\"%s\": {\"auth\": \"%s\"}}}" .Values.privateRegistry.registryUrl (printf "%s:%s" .Values.privateRegistry.registryUser .Values.privateRegistry.registryPasswd | b64enc) | b64enc }} +{{- end }} + +{{- /* +longhorn.labels generates the standard Helm labels. +*/ -}} +{{- define "longhorn.labels" -}} +app.kubernetes.io/name: {{ template "longhorn.name" . }} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +app.kubernetes.io/instance: {{ .Release.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +{{- end -}} + + +{{- define "system_default_registry" -}} +{{- if .Values.global.cattle.systemDefaultRegistry -}} +{{- printf "%s/" .Values.global.cattle.systemDefaultRegistry -}} +{{- else -}} +{{- "" -}} +{{- end -}} +{{- end -}} + +{{- define "registry_url" -}} +{{- if .Values.privateRegistry.registryUrl -}} +{{- printf "%s/" .Values.privateRegistry.registryUrl -}} +{{- else -}} +{{ include "system_default_registry" . }} +{{- end -}} +{{- end -}} + +{{- /* + define the longhorn release namespace +*/ -}} +{{- define "release_namespace" -}} +{{- if .Values.namespaceOverride -}} +{{- .Values.namespaceOverride -}} +{{- else -}} +{{- .Release.Namespace -}} +{{- end -}} +{{- end -}} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/clusterrole.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/clusterrole.yaml new file mode 100644 index 0000000000..f6e069f004 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/clusterrole.yaml @@ -0,0 +1,77 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: longhorn-role + labels: {{- include "longhorn.labels" . | nindent 4 }} +rules: +- apiGroups: + - apiextensions.k8s.io + resources: + - customresourcedefinitions + verbs: + - "*" +- apiGroups: [""] + resources: ["pods", "events", "persistentvolumes", "persistentvolumeclaims","persistentvolumeclaims/status", "nodes", "proxy/nodes", "pods/log", "secrets", "services", "endpoints", "configmaps", "serviceaccounts"] + verbs: ["*"] +- apiGroups: [""] + resources: ["namespaces"] + verbs: ["get", "list"] +- apiGroups: ["apps"] + resources: ["daemonsets", "statefulsets", "deployments"] + verbs: ["*"] +- apiGroups: ["batch"] + resources: ["jobs", "cronjobs"] + verbs: ["*"] +- apiGroups: ["policy"] + resources: ["poddisruptionbudgets", "podsecuritypolicies"] + verbs: ["*"] +- apiGroups: ["scheduling.k8s.io"] + resources: ["priorityclasses"] + verbs: ["watch", "list"] +- apiGroups: ["storage.k8s.io"] + resources: ["storageclasses", "volumeattachments", "volumeattachments/status", "csinodes", "csidrivers"] + verbs: ["*"] +- apiGroups: ["snapshot.storage.k8s.io"] + resources: ["volumesnapshotclasses", "volumesnapshots", "volumesnapshotcontents", "volumesnapshotcontents/status"] + verbs: ["*"] +- apiGroups: ["longhorn.io"] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + {{- if .Values.openshift.enabled }} + "engineimages/finalizers", "nodes/finalizers", "instancemanagers/finalizers", + {{- end }} + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status", "backupbackingimages", "backupbackingimages/status"] + verbs: ["*"] +- apiGroups: ["coordination.k8s.io"] + resources: ["leases"] + verbs: ["*"] +- apiGroups: ["metrics.k8s.io"] + resources: ["pods", "nodes"] + verbs: ["get", "list"] +- apiGroups: ["apiregistration.k8s.io"] + resources: ["apiservices"] + verbs: ["list", "watch"] +- apiGroups: ["admissionregistration.k8s.io"] + resources: ["mutatingwebhookconfigurations", "validatingwebhookconfigurations"] + verbs: ["get", "list", "create", "patch", "delete"] +- apiGroups: ["rbac.authorization.k8s.io"] + resources: ["roles", "rolebindings", "clusterrolebindings", "clusterroles"] + verbs: ["*"] +{{- if .Values.openshift.enabled }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: longhorn-ocp-privileged-role + labels: {{- include "longhorn.labels" . | nindent 4 }} +rules: +- apiGroups: ["security.openshift.io"] + resources: ["securitycontextconstraints"] + resourceNames: ["anyuid", "privileged"] + verbs: ["use"] +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/clusterrolebinding.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/clusterrolebinding.yaml new file mode 100644 index 0000000000..2e34f014ce --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/clusterrolebinding.yaml @@ -0,0 +1,49 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-bind + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: longhorn-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-support-bundle + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-admin +subjects: +- kind: ServiceAccount + name: longhorn-support-bundle + namespace: {{ include "release_namespace" . }} +{{- if .Values.openshift.enabled }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: longhorn-ocp-privileged-bind + labels: {{- include "longhorn.labels" . | nindent 4 }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: longhorn-ocp-privileged-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: longhorn-ui-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: default # supportbundle-agent-support-bundle uses default sa + namespace: {{ include "release_namespace" . }} +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/daemonset-sa.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/daemonset-sa.yaml new file mode 100644 index 0000000000..bbcd59fd1e --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/daemonset-sa.yaml @@ -0,0 +1,167 @@ +apiVersion: apps/v1 +kind: DaemonSet +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-manager + name: longhorn-manager + namespace: {{ include "release_namespace" . }} +spec: + selector: + matchLabels: + app: longhorn-manager + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-manager + {{- with .Values.annotations }} + annotations: + {{- toYaml . | nindent 8 }} + {{- end }} + spec: + containers: + - name: longhorn-manager + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + privileged: true + command: + - longhorn-manager + - -d + {{- if eq .Values.longhornManager.log.format "json" }} + - -j + {{- end }} + - daemon + - --engine-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.engine.repository }}:{{ .Values.image.longhorn.engine.tag }}" + - --instance-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.instanceManager.repository }}:{{ .Values.image.longhorn.instanceManager.tag }}" + - --share-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.shareManager.repository }}:{{ .Values.image.longhorn.shareManager.tag }}" + - --backing-image-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.backingImageManager.repository }}:{{ .Values.image.longhorn.backingImageManager.tag }}" + - --support-bundle-manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.supportBundleKit.repository }}:{{ .Values.image.longhorn.supportBundleKit.tag }}" + - --manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }}" + - --service-account + - longhorn-service-account + {{- if .Values.preUpgradeChecker.upgradeVersionCheck}} + - --upgrade-version-check + {{- end }} + ports: + - containerPort: 9500 + name: manager + - containerPort: 9501 + name: conversion-wh + - containerPort: 9502 + name: admission-wh + - containerPort: 9503 + name: recov-backend + readinessProbe: + httpGet: + path: /v1/healthz + port: 9501 + scheme: HTTPS + volumeMounts: + - name: dev + mountPath: /host/dev/ + - name: proc + mountPath: /host/proc/ + - name: longhorn + mountPath: /var/lib/longhorn/ + mountPropagation: Bidirectional + - name: longhorn-grpc-tls + mountPath: /tls-files/ + {{- if .Values.enableGoCoverDir }} + - name: go-cover-dir + mountPath: /go-cover-dir/ + {{- end }} + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: POD_IP + valueFrom: + fieldRef: + fieldPath: status.podIP + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + {{- if .Values.enableGoCoverDir }} + - name: GOCOVERDIR + value: /go-cover-dir/ + {{- end }} + volumes: + - name: dev + hostPath: + path: /dev/ + - name: proc + hostPath: + path: /proc/ + - name: longhorn + hostPath: + path: /var/lib/longhorn/ + {{- if .Values.enableGoCoverDir }} + - name: go-cover-dir + hostPath: + path: /go-cover-dir/ + type: DirectoryOrCreate + {{- end }} + - name: longhorn-grpc-tls + secret: + secretName: longhorn-grpc-tls + optional: true + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} + serviceAccountName: longhorn-service-account + updateStrategy: + rollingUpdate: + maxUnavailable: "100%" +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-manager + name: longhorn-backend + namespace: {{ include "release_namespace" . }} + {{- if .Values.longhornManager.serviceAnnotations }} + annotations: +{{ toYaml .Values.longhornManager.serviceAnnotations | indent 4 }} + {{- end }} +spec: + type: {{ .Values.service.manager.type }} + selector: + app: longhorn-manager + ports: + - name: manager + port: 9500 + targetPort: manager + {{- if .Values.service.manager.nodePort }} + nodePort: {{ .Values.service.manager.nodePort }} + {{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/default-setting.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/default-setting.yaml new file mode 100644 index 0000000000..5261f7fef8 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/default-setting.yaml @@ -0,0 +1,229 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-default-setting + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +data: + default-setting.yaml: |- + {{- if not (kindIs "invalid" .Values.defaultSettings.backupTarget) }} + backup-target: {{ .Values.defaultSettings.backupTarget }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupTargetCredentialSecret) }} + backup-target-credential-secret: {{ .Values.defaultSettings.backupTargetCredentialSecret }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowRecurringJobWhileVolumeDetached) }} + allow-recurring-job-while-volume-detached: {{ .Values.defaultSettings.allowRecurringJobWhileVolumeDetached }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.createDefaultDiskLabeledNodes) }} + create-default-disk-labeled-nodes: {{ .Values.defaultSettings.createDefaultDiskLabeledNodes }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultDataPath) }} + default-data-path: {{ .Values.defaultSettings.defaultDataPath }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaSoftAntiAffinity) }} + replica-soft-anti-affinity: {{ .Values.defaultSettings.replicaSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaAutoBalance) }} + replica-auto-balance: {{ .Values.defaultSettings.replicaAutoBalance }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageOverProvisioningPercentage) }} + storage-over-provisioning-percentage: {{ .Values.defaultSettings.storageOverProvisioningPercentage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageMinimalAvailablePercentage) }} + storage-minimal-available-percentage: {{ .Values.defaultSettings.storageMinimalAvailablePercentage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageReservedPercentageForDefaultDisk) }} + storage-reserved-percentage-for-default-disk: {{ .Values.defaultSettings.storageReservedPercentageForDefaultDisk }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.upgradeChecker) }} + upgrade-checker: {{ .Values.defaultSettings.upgradeChecker }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultReplicaCount) }} + default-replica-count: {{ .Values.defaultSettings.defaultReplicaCount }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultDataLocality) }} + default-data-locality: {{ .Values.defaultSettings.defaultDataLocality }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.defaultLonghornStaticStorageClass) }} + default-longhorn-static-storage-class: {{ .Values.defaultSettings.defaultLonghornStaticStorageClass }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupstorePollInterval) }} + backupstore-poll-interval: {{ .Values.defaultSettings.backupstorePollInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.failedBackupTTL) }} + failed-backup-ttl: {{ .Values.defaultSettings.failedBackupTTL }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.restoreVolumeRecurringJobs) }} + restore-volume-recurring-jobs: {{ .Values.defaultSettings.restoreVolumeRecurringJobs }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringSuccessfulJobsHistoryLimit) }} + recurring-successful-jobs-history-limit: {{ .Values.defaultSettings.recurringSuccessfulJobsHistoryLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringJobMaxRetention) }} + recurring-job-max-retention: {{ .Values.defaultSettings.recurringJobMaxRetention }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.recurringFailedJobsHistoryLimit) }} + recurring-failed-jobs-history-limit: {{ .Values.defaultSettings.recurringFailedJobsHistoryLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.supportBundleFailedHistoryLimit) }} + support-bundle-failed-history-limit: {{ .Values.defaultSettings.supportBundleFailedHistoryLimit }} + {{- end }} + {{- if or (not (kindIs "invalid" .Values.defaultSettings.taintToleration)) (.Values.global.cattle.windowsCluster.enabled) }} + taint-toleration: {{ $windowsDefaultSettingTaintToleration := list }}{{ $defaultSettingTaintToleration := list -}} + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.defaultSetting.taintToleration -}} + {{- $windowsDefaultSettingTaintToleration = .Values.global.cattle.windowsCluster.defaultSetting.taintToleration -}} + {{- end -}} + {{- if not (kindIs "invalid" .Values.defaultSettings.taintToleration) -}} + {{- $defaultSettingTaintToleration = .Values.defaultSettings.taintToleration -}} + {{- end -}} + {{- $taintToleration := list $windowsDefaultSettingTaintToleration $defaultSettingTaintToleration }}{{ join ";" (compact $taintToleration) -}} + {{- end }} + {{- if or (not (kindIs "invalid" .Values.defaultSettings.systemManagedComponentsNodeSelector)) (.Values.global.cattle.windowsCluster.enabled) }} + system-managed-components-node-selector: {{ $windowsDefaultSettingNodeSelector := list }}{{ $defaultSettingNodeSelector := list -}} + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.defaultSetting.systemManagedComponentsNodeSelector -}} + {{ $windowsDefaultSettingNodeSelector = .Values.global.cattle.windowsCluster.defaultSetting.systemManagedComponentsNodeSelector -}} + {{- end -}} + {{- if not (kindIs "invalid" .Values.defaultSettings.systemManagedComponentsNodeSelector) -}} + {{- $defaultSettingNodeSelector = .Values.defaultSettings.systemManagedComponentsNodeSelector -}} + {{- end -}} + {{- $nodeSelector := list $windowsDefaultSettingNodeSelector $defaultSettingNodeSelector }}{{ join ";" (compact $nodeSelector) -}} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.priorityClass) }} + priority-class: {{ .Values.defaultSettings.priorityClass }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoSalvage) }} + auto-salvage: {{ .Values.defaultSettings.autoSalvage }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly) }} + auto-delete-pod-when-volume-detached-unexpectedly: {{ .Values.defaultSettings.autoDeletePodWhenVolumeDetachedUnexpectedly }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableSchedulingOnCordonedNode) }} + disable-scheduling-on-cordoned-node: {{ .Values.defaultSettings.disableSchedulingOnCordonedNode }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaZoneSoftAntiAffinity) }} + replica-zone-soft-anti-affinity: {{ .Values.defaultSettings.replicaZoneSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaDiskSoftAntiAffinity) }} + replica-disk-soft-anti-affinity: {{ .Values.defaultSettings.replicaDiskSoftAntiAffinity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.nodeDownPodDeletionPolicy) }} + node-down-pod-deletion-policy: {{ .Values.defaultSettings.nodeDownPodDeletionPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.nodeDrainPolicy) }} + node-drain-policy: {{ .Values.defaultSettings.nodeDrainPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.detachManuallyAttachedVolumesWhenCordoned) }} + detach-manually-attached-volumes-when-cordoned: {{ .Values.defaultSettings.detachManuallyAttachedVolumesWhenCordoned }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaReplenishmentWaitInterval) }} + replica-replenishment-wait-interval: {{ .Values.defaultSettings.replicaReplenishmentWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentReplicaRebuildPerNodeLimit) }} + concurrent-replica-rebuild-per-node-limit: {{ .Values.defaultSettings.concurrentReplicaRebuildPerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentVolumeBackupRestorePerNodeLimit) }} + concurrent-volume-backup-restore-per-node-limit: {{ .Values.defaultSettings.concurrentVolumeBackupRestorePerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableRevisionCounter) }} + disable-revision-counter: {{ .Values.defaultSettings.disableRevisionCounter }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.systemManagedPodsImagePullPolicy) }} + system-managed-pods-image-pull-policy: {{ .Values.defaultSettings.systemManagedPodsImagePullPolicy }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowVolumeCreationWithDegradedAvailability) }} + allow-volume-creation-with-degraded-availability: {{ .Values.defaultSettings.allowVolumeCreationWithDegradedAvailability }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupSystemGeneratedSnapshot) }} + auto-cleanup-system-generated-snapshot: {{ .Values.defaultSettings.autoCleanupSystemGeneratedSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.autoCleanupRecurringJobBackupSnapshot) }} + auto-cleanup-recurring-job-backup-snapshot: {{ .Values.defaultSettings.autoCleanupRecurringJobBackupSnapshot }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit) }} + concurrent-automatic-engine-upgrade-per-node-limit: {{ .Values.defaultSettings.concurrentAutomaticEngineUpgradePerNodeLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backingImageCleanupWaitInterval) }} + backing-image-cleanup-wait-interval: {{ .Values.defaultSettings.backingImageCleanupWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backingImageRecoveryWaitInterval) }} + backing-image-recovery-wait-interval: {{ .Values.defaultSettings.backingImageRecoveryWaitInterval }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.guaranteedInstanceManagerCPU) }} + guaranteed-instance-manager-cpu: {{ .Values.defaultSettings.guaranteedInstanceManagerCPU }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.kubernetesClusterAutoscalerEnabled) }} + kubernetes-cluster-autoscaler-enabled: {{ .Values.defaultSettings.kubernetesClusterAutoscalerEnabled }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.orphanAutoDeletion) }} + orphan-auto-deletion: {{ .Values.defaultSettings.orphanAutoDeletion }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.storageNetwork) }} + storage-network: {{ .Values.defaultSettings.storageNetwork }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.deletingConfirmationFlag) }} + deleting-confirmation-flag: {{ .Values.defaultSettings.deletingConfirmationFlag }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.engineReplicaTimeout) }} + engine-replica-timeout: {{ .Values.defaultSettings.engineReplicaTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrity) }} + snapshot-data-integrity: {{ .Values.defaultSettings.snapshotDataIntegrity }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation) }} + snapshot-data-integrity-immediate-check-after-snapshot-creation: {{ .Values.defaultSettings.snapshotDataIntegrityImmediateCheckAfterSnapshotCreation }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotDataIntegrityCronjob) }} + snapshot-data-integrity-cronjob: {{ .Values.defaultSettings.snapshotDataIntegrityCronjob }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.removeSnapshotsDuringFilesystemTrim) }} + remove-snapshots-during-filesystem-trim: {{ .Values.defaultSettings.removeSnapshotsDuringFilesystemTrim }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.fastReplicaRebuildEnabled) }} + fast-replica-rebuild-enabled: {{ .Values.defaultSettings.fastReplicaRebuildEnabled }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.replicaFileSyncHttpClientTimeout) }} + replica-file-sync-http-client-timeout: {{ .Values.defaultSettings.replicaFileSyncHttpClientTimeout }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.logLevel) }} + log-level: {{ .Values.defaultSettings.logLevel }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupCompressionMethod) }} + backup-compression-method: {{ .Values.defaultSettings.backupCompressionMethod }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.backupConcurrentLimit) }} + backup-concurrent-limit: {{ .Values.defaultSettings.backupConcurrentLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.restoreConcurrentLimit) }} + restore-concurrent-limit: {{ .Values.defaultSettings.restoreConcurrentLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v1DataEngine) }} + v1-data-engine: {{ .Values.defaultSettings.v1DataEngine }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngine) }} + v2-data-engine: {{ .Values.defaultSettings.v2DataEngine }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineHugepageLimit) }} + v2-data-engine-hugepage-limit: {{ .Values.defaultSettings.v2DataEngineHugepageLimit }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.offlineReplicaRebuilding) }} + offline-replica-rebuilding: {{ .Values.defaultSettings.offlineReplicaRebuilding }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowEmptyNodeSelectorVolume) }} + allow-empty-node-selector-volume: {{ .Values.defaultSettings.allowEmptyNodeSelectorVolume }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowEmptyDiskSelectorVolume) }} + allow-empty-disk-selector-volume: {{ .Values.defaultSettings.allowEmptyDiskSelectorVolume }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.allowCollectingLonghornUsageMetrics) }} + allow-collecting-longhorn-usage-metrics: {{ .Values.defaultSettings.allowCollectingLonghornUsageMetrics }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.disableSnapshotPurge) }} + disable-snapshot-purge: {{ .Values.defaultSettings.disableSnapshotPurge }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU) }} + v2-data-engine-guaranteed-instance-manager-cpu: {{ .Values.defaultSettings.v2DataEngineGuaranteedInstanceManagerCPU }} + {{- end }} + {{- if not (kindIs "invalid" .Values.defaultSettings.snapshotMaxCount) }} + snapshot-max-count: {{ .Values.defaultSettings.snapshotMaxCount }} + {{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/deployment-driver.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/deployment-driver.yaml new file mode 100644 index 0000000000..3ac582dcbc --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/deployment-driver.yaml @@ -0,0 +1,132 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: longhorn-driver-deployer + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + replicas: 1 + selector: + matchLabels: + app: longhorn-driver-deployer + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-driver-deployer + spec: + initContainers: + - name: wait-longhorn-manager + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + command: ['sh', '-c', 'while [ $(curl -m 1 -s -o /dev/null -w "%{http_code}" http://longhorn-backend:9500/v1) != "200" ]; do echo waiting; sleep 2; done'] + containers: + - name: longhorn-driver-deployer + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - -d + - deploy-driver + - --manager-image + - "{{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }}" + - --manager-url + - http://longhorn-backend:9500/v1 + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + - name: SERVICE_ACCOUNT + valueFrom: + fieldRef: + fieldPath: spec.serviceAccountName + {{- if .Values.csi.kubeletRootDir }} + - name: KUBELET_ROOT_DIR + value: {{ .Values.csi.kubeletRootDir }} + {{- end }} + {{- if and .Values.image.csi.attacher.repository .Values.image.csi.attacher.tag }} + - name: CSI_ATTACHER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.attacher.repository }}:{{ .Values.image.csi.attacher.tag }}" + {{- end }} + {{- if and .Values.image.csi.provisioner.repository .Values.image.csi.provisioner.tag }} + - name: CSI_PROVISIONER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.provisioner.repository }}:{{ .Values.image.csi.provisioner.tag }}" + {{- end }} + {{- if and .Values.image.csi.nodeDriverRegistrar.repository .Values.image.csi.nodeDriverRegistrar.tag }} + - name: CSI_NODE_DRIVER_REGISTRAR_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.nodeDriverRegistrar.repository }}:{{ .Values.image.csi.nodeDriverRegistrar.tag }}" + {{- end }} + {{- if and .Values.image.csi.resizer.repository .Values.image.csi.resizer.tag }} + - name: CSI_RESIZER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.resizer.repository }}:{{ .Values.image.csi.resizer.tag }}" + {{- end }} + {{- if and .Values.image.csi.snapshotter.repository .Values.image.csi.snapshotter.tag }} + - name: CSI_SNAPSHOTTER_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.snapshotter.repository }}:{{ .Values.image.csi.snapshotter.tag }}" + {{- end }} + {{- if and .Values.image.csi.livenessProbe.repository .Values.image.csi.livenessProbe.tag }} + - name: CSI_LIVENESS_PROBE_IMAGE + value: "{{ template "registry_url" . }}{{ .Values.image.csi.livenessProbe.repository }}:{{ .Values.image.csi.livenessProbe.tag }}" + {{- end }} + {{- if .Values.csi.attacherReplicaCount }} + - name: CSI_ATTACHER_REPLICA_COUNT + value: {{ .Values.csi.attacherReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.provisionerReplicaCount }} + - name: CSI_PROVISIONER_REPLICA_COUNT + value: {{ .Values.csi.provisionerReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.resizerReplicaCount }} + - name: CSI_RESIZER_REPLICA_COUNT + value: {{ .Values.csi.resizerReplicaCount | quote }} + {{- end }} + {{- if .Values.csi.snapshotterReplicaCount }} + - name: CSI_SNAPSHOTTER_REPLICA_COUNT + value: {{ .Values.csi.snapshotterReplicaCount | quote }} + {{- end }} + {{- if .Values.enableGoCoverDir }} + - name: GOCOVERDIR + value: /go-cover-dir/ + volumeMounts: + - name: go-cover-dir + mountPath: /go-cover-dir/ + {{- end }} + + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornDriver.priorityClass }} + priorityClassName: {{ .Values.longhornDriver.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornDriver.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornDriver.tolerations }} +{{ default .Values.global.tolerations .Values.longhornDriver.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornDriver.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornDriver.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornDriver.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} + serviceAccountName: longhorn-service-account + securityContext: + runAsUser: 0 + {{- if .Values.enableGoCoverDir }} + volumes: + - name: go-cover-dir + hostPath: + path: /go-cover-dir/ + type: DirectoryOrCreate + {{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/deployment-ui.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/deployment-ui.yaml new file mode 100644 index 0000000000..22c443aeba --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/deployment-ui.yaml @@ -0,0 +1,182 @@ +{{- if .Values.openshift.enabled }} +{{- if .Values.openshift.ui.route }} +# https://github.com/openshift/oauth-proxy/blob/master/contrib/sidecar.yaml +# Create a proxy service account and ensure it will use the route "proxy" +# Create a secure connection to the proxy via a route +apiVersion: route.openshift.io/v1 +kind: Route +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: {{ .Values.openshift.ui.route }} + namespace: {{ include "release_namespace" . }} +spec: + to: + kind: Service + name: longhorn-ui + tls: + termination: reencrypt +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: longhorn-ui + namespace: {{ include "release_namespace" . }} + annotations: + service.alpha.openshift.io/serving-cert-secret-name: longhorn-ui-tls +spec: + ports: + - name: longhorn-ui + port: {{ .Values.openshift.ui.port | default 443 }} + targetPort: {{ .Values.openshift.ui.proxy | default 8443 }} + selector: + app: longhorn-ui +--- +{{- end }} +{{- end }} +apiVersion: apps/v1 +kind: Deployment +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + name: longhorn-ui + namespace: {{ include "release_namespace" . }} +spec: + replicas: {{ .Values.longhornUI.replicas }} + selector: + matchLabels: + app: longhorn-ui + template: + metadata: + labels: {{- include "longhorn.labels" . | nindent 8 }} + app: longhorn-ui + spec: + serviceAccountName: longhorn-ui-service-account + affinity: + podAntiAffinity: + preferredDuringSchedulingIgnoredDuringExecution: + - weight: 1 + podAffinityTerm: + labelSelector: + matchExpressions: + - key: app + operator: In + values: + - longhorn-ui + topologyKey: kubernetes.io/hostname + containers: + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + - name: oauth-proxy + image: {{ template "registry_url" . }}{{ .Values.image.openshift.oauthProxy.repository }}:{{ .Values.image.openshift.oauthProxy.tag }} + imagePullPolicy: IfNotPresent + ports: + - containerPort: {{ .Values.openshift.ui.proxy | default 8443 }} + name: public + args: + - --https-address=:{{ .Values.openshift.ui.proxy | default 8443 }} + - --provider=openshift + - --openshift-service-account=longhorn-ui-service-account + - --upstream=http://localhost:8000 + - --tls-cert=/etc/tls/private/tls.crt + - --tls-key=/etc/tls/private/tls.key + - --cookie-secret=SECRET + - --openshift-sar={"namespace":"{{ include "release_namespace" . }}","group":"longhorn.io","resource":"setting","verb":"delete"} + volumeMounts: + - mountPath: /etc/tls/private + name: longhorn-ui-tls + {{- end }} + {{- end }} + - name: longhorn-ui + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.ui.repository }}:{{ .Values.image.longhorn.ui.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + volumeMounts: + - name : nginx-cache + mountPath: /var/cache/nginx/ + - name : nginx-config + mountPath: /var/config/nginx/ + - name: var-run + mountPath: /var/run/ + ports: + - containerPort: 8000 + name: http + env: + - name: LONGHORN_MANAGER_IP + value: "http://longhorn-backend:9500" + - name: LONGHORN_UI_PORT + value: "8000" + volumes: + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + - name: longhorn-ui-tls + secret: + secretName: longhorn-ui-tls + {{- end }} + {{- end }} + - emptyDir: {} + name: nginx-cache + - emptyDir: {} + name: nginx-config + - emptyDir: {} + name: var-run + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornUI.priorityClass }} + priorityClassName: {{ .Values.longhornUI.priorityClass | quote }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornUI.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornUI.tolerations }} +{{ default .Values.global.tolerations .Values.longhornUI.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornUI.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornUI.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornUI.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} +--- +kind: Service +apiVersion: v1 +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ui + {{- if eq .Values.service.ui.type "Rancher-Proxy" }} + kubernetes.io/cluster-service: "true" + {{- end }} + name: longhorn-frontend + namespace: {{ include "release_namespace" . }} +spec: + {{- if eq .Values.service.ui.type "Rancher-Proxy" }} + type: ClusterIP + {{- else }} + type: {{ .Values.service.ui.type }} + {{- end }} + {{- if and .Values.service.ui.loadBalancerIP (eq .Values.service.ui.type "LoadBalancer") }} + loadBalancerIP: {{ .Values.service.ui.loadBalancerIP }} + {{- end }} + {{- if and (eq .Values.service.ui.type "LoadBalancer") .Values.service.ui.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.service.ui.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + selector: + app: longhorn-ui + ports: + - name: http + port: 80 + targetPort: http + {{- if .Values.service.ui.nodePort }} + nodePort: {{ .Values.service.ui.nodePort }} + {{- else }} + nodePort: null + {{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/ingress.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/ingress.yaml new file mode 100644 index 0000000000..9038ff0cc1 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/ingress.yaml @@ -0,0 +1,37 @@ +{{- if .Values.ingress.enabled }} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: longhorn-ingress + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-ingress + annotations: + {{- if .Values.ingress.secureBackends }} + ingress.kubernetes.io/secure-backends: "true" + {{- end }} + {{- range $key, $value := .Values.ingress.annotations }} + {{ $key }}: {{ $value | quote }} + {{- end }} +spec: + {{- if .Values.ingress.ingressClassName }} + ingressClassName: {{ .Values.ingress.ingressClassName }} + {{- end }} + rules: + - host: {{ .Values.ingress.host }} + http: + paths: + - path: {{ default "" .Values.ingress.path }} + pathType: ImplementationSpecific + backend: + service: + name: longhorn-frontend + port: + number: 80 +{{- if .Values.ingress.tls }} + tls: + - hosts: + - {{ .Values.ingress.host }} + secretName: {{ .Values.ingress.tlsSecret }} +{{- end }} +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/backing-image-data-source-network-policy.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/backing-image-data-source-network-policy.yaml new file mode 100644 index 0000000000..7204d63caa --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/backing-image-data-source-network-policy.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: backing-image-data-source + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/backing-image-manager-network-policy.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/backing-image-manager-network-policy.yaml new file mode 100644 index 0000000000..119ebf08a1 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/backing-image-manager-network-policy.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: backing-image-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/instance-manager-networking.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/instance-manager-networking.yaml new file mode 100644 index 0000000000..332aa2c2fe --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/instance-manager-networking.yaml @@ -0,0 +1,27 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: instance-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + longhorn.io/component: instance-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + longhorn.io/component: instance-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-manager + - podSelector: + matchLabels: + longhorn.io/component: backing-image-data-source +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/manager-network-policy.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/manager-network-policy.yaml new file mode 100644 index 0000000000..6f94029a53 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/manager-network-policy.yaml @@ -0,0 +1,35 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-manager + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - from: + - podSelector: + matchLabels: + app: longhorn-manager + - podSelector: + matchLabels: + app: longhorn-ui + - podSelector: + matchLabels: + app: longhorn-csi-plugin + - podSelector: + matchLabels: + longhorn.io/managed-by: longhorn-manager + matchExpressions: + - { key: recurring-job.longhorn.io, operator: Exists } + - podSelector: + matchExpressions: + - { key: longhorn.io/job-task, operator: Exists } + - podSelector: + matchLabels: + app: longhorn-driver-deployer +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/recovery-backend-network-policy.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/recovery-backend-network-policy.yaml new file mode 100644 index 0000000000..6e34dadfc2 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/recovery-backend-network-policy.yaml @@ -0,0 +1,17 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-recovery-backend + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9503 +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/ui-frontend-network-policy.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/ui-frontend-network-policy.yaml new file mode 100644 index 0000000000..6f37065980 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/ui-frontend-network-policy.yaml @@ -0,0 +1,46 @@ +{{- if and .Values.networkPolicies.enabled .Values.ingress.enabled (not (eq .Values.networkPolicies.type "")) }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-ui-frontend + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-ui + policyTypes: + - Ingress + ingress: + - from: + {{- if eq .Values.networkPolicies.type "rke1"}} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: ingress-nginx + podSelector: + matchLabels: + app.kubernetes.io/component: controller + app.kubernetes.io/instance: ingress-nginx + app.kubernetes.io/name: ingress-nginx + {{- else if eq .Values.networkPolicies.type "rke2" }} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + podSelector: + matchLabels: + app.kubernetes.io/component: controller + app.kubernetes.io/instance: rke2-ingress-nginx + app.kubernetes.io/name: rke2-ingress-nginx + {{- else if eq .Values.networkPolicies.type "k3s" }} + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + podSelector: + matchLabels: + app.kubernetes.io/name: traefik + ports: + - port: 8000 + protocol: TCP + - port: 80 + protocol: TCP + {{- end }} +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/webhook-network-policy.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/webhook-network-policy.yaml new file mode 100644 index 0000000000..3575763d39 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/network-policies/webhook-network-policy.yaml @@ -0,0 +1,33 @@ +{{- if .Values.networkPolicies.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9501 +--- +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: longhorn-admission-webhook + namespace: {{ include "release_namespace" . }} +spec: + podSelector: + matchLabels: + app: longhorn-manager + policyTypes: + - Ingress + ingress: + - ports: + - protocol: TCP + port: 9502 +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/postupgrade-job.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/postupgrade-job.yaml new file mode 100644 index 0000000000..56efd38e9b --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/postupgrade-job.yaml @@ -0,0 +1,56 @@ +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": post-upgrade + "helm.sh/hook-delete-policy": hook-succeeded,before-hook-creation + name: longhorn-post-upgrade + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-post-upgrade + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-post-upgrade + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - post-upgrade + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: OnFailure + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/preupgrade-job.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/preupgrade-job.yaml new file mode 100644 index 0000000000..2b8333d89e --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/preupgrade-job.yaml @@ -0,0 +1,55 @@ +{{- if and .Values.preUpgradeChecker.jobEnabled .Values.preUpgradeChecker.upgradeVersionCheck}} +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": pre-upgrade + "helm.sh/hook-delete-policy": hook-succeeded,before-hook-creation,hook-failed + name: longhorn-pre-upgrade + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-pre-upgrade + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-pre-upgrade + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - pre-upgrade + env: + - name: POD_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: OnFailure + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/priorityclass.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/priorityclass.yaml new file mode 100644 index 0000000000..208adc84a2 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/priorityclass.yaml @@ -0,0 +1,9 @@ +apiVersion: scheduling.k8s.io/v1 +kind: PriorityClass +metadata: + name: "longhorn-critical" + labels: {{- include "longhorn.labels" . | nindent 4 }} +description: "Ensure Longhorn pods have the highest priority to prevent any unexpected eviction by the Kubernetes scheduler under node pressure" +globalDefault: false +preemptionPolicy: PreemptLowerPriority +value: 1000000000 diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/psp.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/psp.yaml new file mode 100644 index 0000000000..a2dfc05bef --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/psp.yaml @@ -0,0 +1,66 @@ +{{- if .Values.enablePSP }} +apiVersion: policy/v1beta1 +kind: PodSecurityPolicy +metadata: + name: longhorn-psp + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + privileged: true + allowPrivilegeEscalation: true + requiredDropCapabilities: + - NET_RAW + allowedCapabilities: + - SYS_ADMIN + hostNetwork: false + hostIPC: false + hostPID: true + runAsUser: + rule: RunAsAny + seLinux: + rule: RunAsAny + fsGroup: + rule: RunAsAny + supplementalGroups: + rule: RunAsAny + volumes: + - configMap + - downwardAPI + - emptyDir + - secret + - projected + - hostPath +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: longhorn-psp-role + labels: {{- include "longhorn.labels" . | nindent 4 }} + namespace: {{ include "release_namespace" . }} +rules: +- apiGroups: + - policy + resources: + - podsecuritypolicies + verbs: + - use + resourceNames: + - longhorn-psp +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: longhorn-psp-binding + labels: {{- include "longhorn.labels" . | nindent 4 }} + namespace: {{ include "release_namespace" . }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: longhorn-psp-role +subjects: +- kind: ServiceAccount + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} +- kind: ServiceAccount + name: default + namespace: {{ include "release_namespace" . }} +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/registry-secret.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/registry-secret.yaml new file mode 100644 index 0000000000..3c6b1dc510 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/registry-secret.yaml @@ -0,0 +1,13 @@ +{{- if .Values.privateRegistry.createSecret }} +{{- if .Values.privateRegistry.registrySecret }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .Values.privateRegistry.registrySecret }} + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +type: kubernetes.io/dockerconfigjson +data: + .dockerconfigjson: {{ template "secret" . }} +{{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/serviceaccount.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/serviceaccount.yaml new file mode 100644 index 0000000000..b0d6dd505b --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/serviceaccount.yaml @@ -0,0 +1,40 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-service-account + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-ui-service-account + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- if .Values.openshift.enabled }} + {{- if .Values.openshift.ui.route }} + {{- if not .Values.serviceAccount.annotations }} + annotations: + {{- end }} + serviceaccounts.openshift.io/oauth-redirectreference.primary: '{"kind":"OAuthRedirectReference","apiVersion":"v1","reference":{"kind":"Route","name":"longhorn-ui"}}' + {{- end }} + {{- end }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: longhorn-support-bundle + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/servicemonitor.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/servicemonitor.yaml new file mode 100644 index 0000000000..3f32961332 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/servicemonitor.yaml @@ -0,0 +1,40 @@ +{{- if .Values.metrics.serviceMonitor.enabled -}} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: longhorn-prometheus-servicemonitor + namespace: {{ include "release_namespace" . }} + labels: + {{- include "longhorn.labels" . | nindent 4 }} + name: longhorn-prometheus-servicemonitor + {{- with .Values.metrics.serviceMonitor.additionalLabels }} + {{- toYaml . | nindent 4 }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: + app: longhorn-manager + namespaceSelector: + matchNames: + - {{ include "release_namespace" . }} + endpoints: + - port: manager + {{- with .Values.metrics.serviceMonitor.interval }} + interval: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ . }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.relabelings }} + relabelings: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.metricRelabelings }} + metricRelabelings: + {{- toYaml . | nindent 8 }} + {{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/services.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/services.yaml new file mode 100644 index 0000000000..9523cabcab --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/services.yaml @@ -0,0 +1,47 @@ +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-conversion-webhook + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + app: longhorn-manager + ports: + - name: conversion-webhook + port: 9501 + targetPort: conversion-wh +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-admission-webhook + name: longhorn-admission-webhook + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + app: longhorn-manager + ports: + - name: admission-webhook + port: 9502 + targetPort: admission-wh +--- +apiVersion: v1 +kind: Service +metadata: + labels: {{- include "longhorn.labels" . | nindent 4 }} + app: longhorn-recovery-backend + name: longhorn-recovery-backend + namespace: {{ include "release_namespace" . }} +spec: + type: ClusterIP + selector: + app: longhorn-manager + ports: + - name: recovery-backend + port: 9503 + targetPort: recov-backend diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/storageclass.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/storageclass.yaml new file mode 100644 index 0000000000..f79699f5e0 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/storageclass.yaml @@ -0,0 +1,50 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-storageclass + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +data: + storageclass.yaml: | + kind: StorageClass + apiVersion: storage.k8s.io/v1 + metadata: + name: longhorn + annotations: + storageclass.kubernetes.io/is-default-class: {{ .Values.persistence.defaultClass | quote }} + provisioner: driver.longhorn.io + allowVolumeExpansion: true + reclaimPolicy: "{{ .Values.persistence.reclaimPolicy }}" + volumeBindingMode: Immediate + parameters: + numberOfReplicas: "{{ .Values.persistence.defaultClassReplicaCount }}" + staleReplicaTimeout: "30" + fromBackup: "" + {{- if .Values.persistence.defaultFsType }} + fsType: "{{ .Values.persistence.defaultFsType }}" + {{- end }} + {{- if .Values.persistence.defaultMkfsParams }} + mkfsParams: "{{ .Values.persistence.defaultMkfsParams }}" + {{- end }} + {{- if .Values.persistence.migratable }} + migratable: "{{ .Values.persistence.migratable }}" + {{- end }} + {{- if .Values.persistence.nfsOptions }} + nfsOptions: "{{ .Values.persistence.nfsOptions }}" + {{- end }} + {{- if .Values.persistence.backingImage.enable }} + backingImage: {{ .Values.persistence.backingImage.name }} + backingImageDataSourceType: {{ .Values.persistence.backingImage.dataSourceType }} + backingImageDataSourceParameters: {{ .Values.persistence.backingImage.dataSourceParameters }} + backingImageChecksum: {{ .Values.persistence.backingImage.expectedChecksum }} + {{- end }} + {{- if .Values.persistence.recurringJobSelector.enable }} + recurringJobSelector: '{{ .Values.persistence.recurringJobSelector.jobList }}' + {{- end }} + dataLocality: {{ .Values.persistence.defaultDataLocality | quote }} + {{- if .Values.persistence.defaultNodeSelector.enable }} + nodeSelector: "{{ .Values.persistence.defaultNodeSelector.selector }}" + {{- end }} + {{- if .Values.persistence.removeSnapshotsDuringFilesystemTrim }} + unmapMarkSnapChainRemoved: "{{ .Values.persistence.removeSnapshotsDuringFilesystemTrim }}" + {{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/tls-secrets.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/tls-secrets.yaml new file mode 100644 index 0000000000..74c43426de --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/tls-secrets.yaml @@ -0,0 +1,16 @@ +{{- if .Values.ingress.enabled }} +{{- range .Values.ingress.secrets }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .name }} + namespace: {{ include "release_namespace" $ }} + labels: {{- include "longhorn.labels" $ | nindent 4 }} + app: longhorn +type: kubernetes.io/tls +data: + tls.crt: {{ .certificate | b64enc }} + tls.key: {{ .key | b64enc }} +--- +{{- end }} +{{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/uninstall-job.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/uninstall-job.yaml new file mode 100644 index 0000000000..1ab46207c3 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/uninstall-job.yaml @@ -0,0 +1,57 @@ +apiVersion: batch/v1 +kind: Job +metadata: + annotations: + "helm.sh/hook": pre-delete + "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded + name: longhorn-uninstall + namespace: {{ include "release_namespace" . }} + labels: {{- include "longhorn.labels" . | nindent 4 }} +spec: + activeDeadlineSeconds: 900 + backoffLimit: 1 + template: + metadata: + name: longhorn-uninstall + labels: {{- include "longhorn.labels" . | nindent 8 }} + spec: + containers: + - name: longhorn-uninstall + image: {{ template "registry_url" . }}{{ .Values.image.longhorn.manager.repository }}:{{ .Values.image.longhorn.manager.tag }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - longhorn-manager + - uninstall + - --force + env: + - name: LONGHORN_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + restartPolicy: Never + {{- if .Values.privateRegistry.registrySecret }} + imagePullSecrets: + - name: {{ .Values.privateRegistry.registrySecret }} + {{- end }} + {{- if .Values.longhornManager.priorityClass }} + priorityClassName: {{ .Values.longhornManager.priorityClass | quote }} + {{- end }} + serviceAccountName: longhorn-service-account + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations .Values.global.cattle.windowsCluster.enabled }} + tolerations: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.tolerations }} +{{ toYaml .Values.global.cattle.windowsCluster.tolerations | indent 6 }} + {{- end }} + {{- if or .Values.global.tolerations .Values.longhornManager.tolerations }} +{{ default .Values.global.tolerations .Values.longhornManager.tolerations | toYaml | indent 6 }} + {{- end }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector .Values.global.cattle.windowsCluster.enabled }} + nodeSelector: + {{- if and .Values.global.cattle.windowsCluster.enabled .Values.global.cattle.windowsCluster.nodeSelector }} +{{ toYaml .Values.global.cattle.windowsCluster.nodeSelector | indent 8 }} + {{- end }} + {{- if or .Values.global.nodeSelector .Values.longhornManager.nodeSelector }} +{{ default .Values.global.nodeSelector .Values.longhornManager.nodeSelector | toYaml | indent 8 }} + {{- end }} + {{- end }} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/userroles.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/userroles.yaml new file mode 100644 index 0000000000..1dbb6be90e --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/userroles.yaml @@ -0,0 +1,53 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-admin" + labels: + rbac.authorization.k8s.io/aggregate-to-admin: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "*" ] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-edit" + labels: + rbac.authorization.k8s.io/aggregate-to-edit: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "*" ] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: "longhorn-view" + labels: + rbac.authorization.k8s.io/aggregate-to-view: "true" +rules: +- apiGroups: [ "longhorn.io" ] + resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings", + "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status", + "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status", + "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status", "backupbackingimages", "backupbackingimages/status", + "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status", + "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status", + "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status", + "volumeattachments", "volumeattachments/status"] + verbs: [ "get", "list", "watch" ] diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/validate-install-crd.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/validate-install-crd.yaml new file mode 100644 index 0000000000..aac4dd9c53 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/validate-install-crd.yaml @@ -0,0 +1,35 @@ +#{{- if gt (len (lookup "rbac.authorization.k8s.io/v1" "ClusterRole" "" "")) 0 -}} +# {{- $found := dict -}} +# {{- set $found "longhorn.io/v1beta1/BackingImageDataSource" false -}} +# {{- set $found "longhorn.io/v1beta1/BackingImageManager" false -}} +# {{- set $found "longhorn.io/v1beta1/BackingImage" false -}} +# {{- set $found "longhorn.io/v1beta1/Backup" false -}} +# {{- set $found "longhorn.io/v1beta2/BackupBackingImage" false -}} +# {{- set $found "longhorn.io/v1beta1/BackupTarget" false -}} +# {{- set $found "longhorn.io/v1beta1/BackupVolume" false -}} +# {{- set $found "longhorn.io/v1beta1/EngineImage" false -}} +# {{- set $found "longhorn.io/v1beta1/Engine" false -}} +# {{- set $found "longhorn.io/v1beta1/InstanceManager" false -}} +# {{- set $found "longhorn.io/v1beta1/Node" false -}} +# {{- set $found "longhorn.io/v1beta2/Orphan" false -}} +# {{- set $found "longhorn.io/v1beta1/RecurringJob" false -}} +# {{- set $found "longhorn.io/v1beta1/Replica" false -}} +# {{- set $found "longhorn.io/v1beta1/Setting" false -}} +# {{- set $found "longhorn.io/v1beta1/ShareManager" false -}} +# {{- set $found "longhorn.io/v1beta2/Snapshot" false -}} +# {{- set $found "longhorn.io/v1beta2/SupportBundle" false -}} +# {{- set $found "longhorn.io/v1beta2/SystemBackup" false -}} +# {{- set $found "longhorn.io/v1beta2/SystemRestore" false -}} +# {{- set $found "longhorn.io/v1beta1/Volume" false -}} +# {{- set $found "longhorn.io/v1beta2/VolumeAttachment" false -}} +# {{- range .Capabilities.APIVersions -}} +# {{- if hasKey $found (toString .) -}} +# {{- set $found (toString .) true -}} +# {{- end -}} +# {{- end -}} +# {{- range $_, $exists := $found -}} +# {{- if (eq $exists false) -}} +# {{- required "Required CRDs are missing. Please install the corresponding CRD chart before installing this chart." "" -}} +# {{- end -}} +# {{- end -}} +#{{- end -}} diff --git a/charts/longhorn/105.0.0+up1.6.3/templates/validate-psp-install.yaml b/charts/longhorn/105.0.0+up1.6.3/templates/validate-psp-install.yaml new file mode 100644 index 0000000000..0df98e3657 --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/templates/validate-psp-install.yaml @@ -0,0 +1,7 @@ +#{{- if gt (len (lookup "rbac.authorization.k8s.io/v1" "ClusterRole" "" "")) 0 -}} +#{{- if .Values.enablePSP }} +#{{- if not (.Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy") }} +#{{- fail "The target cluster does not have the PodSecurityPolicy API resource. Please disable PSPs in this chart before proceeding." -}} +#{{- end }} +#{{- end }} +#{{- end }} \ No newline at end of file diff --git a/charts/longhorn/105.0.0+up1.6.3/values.yaml b/charts/longhorn/105.0.0+up1.6.3/values.yaml new file mode 100644 index 0000000000..f199eaf5dd --- /dev/null +++ b/charts/longhorn/105.0.0+up1.6.3/values.yaml @@ -0,0 +1,504 @@ +# Default values for longhorn. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. +global: + # -- Toleration for nodes allowed to run user-deployed components such as Longhorn Manager, Longhorn UI, and Longhorn Driver Deployer. + tolerations: [] + # -- Node selector for nodes allowed to run user-deployed components such as Longhorn Manager, Longhorn UI, and Longhorn Driver Deployer. + nodeSelector: {} + cattle: + # -- Default system registry. + systemDefaultRegistry: "" + windowsCluster: + # -- Setting that allows Longhorn to run on a Rancher Windows cluster. + enabled: false + # -- Toleration for Linux nodes that can run user-deployed Longhorn components. + tolerations: + - key: "cattle.io/os" + value: "linux" + effect: "NoSchedule" + operator: "Equal" + # -- Node selector for Linux nodes that can run user-deployed Longhorn components. + nodeSelector: + kubernetes.io/os: "linux" + defaultSetting: + # -- Toleration for system-managed Longhorn components. + taintToleration: cattle.io/os=linux:NoSchedule + # -- Node selector for system-managed Longhorn components. + systemManagedComponentsNodeSelector: kubernetes.io/os:linux + +networkPolicies: + # -- Setting that allows you to enable network policies that control access to Longhorn pods. + enabled: false + # -- Distribution that determines the policy for allowing access for an ingress. (Options: "k3s", "rke2", "rke1") + type: "k3s" + +image: + longhorn: + engine: + # -- Repository for the Longhorn Engine image. + repository: rancher/mirrored-longhornio-longhorn-engine + # -- Specify Longhorn engine image tag + tag: v1.6.3 + manager: + # -- Repository for the Longhorn Manager image. + repository: rancher/mirrored-longhornio-longhorn-manager + # -- Specify Longhorn manager image tag + tag: v1.6.3 + ui: + # -- Repository for the Longhorn UI image. + repository: rancher/mirrored-longhornio-longhorn-ui + # -- Specify Longhorn ui image tag + tag: v1.6.3 + instanceManager: + # -- Repository for the Longhorn Instance Manager image. + repository: rancher/mirrored-longhornio-longhorn-instance-manager + # -- Specify Longhorn instance manager image tag + tag: v1.6.3 + shareManager: + # -- Repository for the Longhorn Share Manager image. + repository: rancher/mirrored-longhornio-longhorn-share-manager + # -- Specify Longhorn share manager image tag + tag: v1.6.3 + backingImageManager: + # -- Repository for the Backing Image Manager image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-backing-image-manager + # -- Specify Longhorn backing image manager image tag + tag: v1.6.3 + supportBundleKit: + # -- Repository for the Longhorn Support Bundle Manager image. + repository: rancher/mirrored-longhornio-support-bundle-kit + # -- Tag for the Longhorn Support Bundle Manager image. + tag: v0.0.43 + csi: + attacher: + # -- Repository for the CSI attacher image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-attacher + # -- Tag for the CSI attacher image. When unspecified, Longhorn uses the default value. + tag: v4.7.0 + provisioner: + # -- Repository for the CSI Provisioner image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-provisioner + # -- Tag for the CSI Provisioner image. When unspecified, Longhorn uses the default value. + tag: v3.6.4 + nodeDriverRegistrar: + # -- Repository for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-node-driver-registrar + # -- Tag for the CSI Node Driver Registrar image. When unspecified, Longhorn uses the default value. + tag: v2.12.0 + resizer: + # -- Repository for the CSI Resizer image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-resizer + # -- Tag for the CSI Resizer image. When unspecified, Longhorn uses the default value. + tag: v1.12.0 + snapshotter: + # -- Repository for the CSI Snapshotter image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-csi-snapshotter + # -- Tag for the CSI Snapshotter image. When unspecified, Longhorn uses the default value. + tag: v6.3.4 + livenessProbe: + # -- Repository for the CSI liveness probe image. When unspecified, Longhorn uses the default value. + repository: rancher/mirrored-longhornio-livenessprobe + # -- Tag for the CSI liveness probe image. When unspecified, Longhorn uses the default value. + tag: v2.14.0 + openshift: + oauthProxy: + # -- Repository for the OAuth Proxy image. This setting applies only to OpenShift users. + repository: rancher/mirrored-longhornio-openshift-origin-oauth-proxy + # -- Tag for the OAuth Proxy image. This setting applies only to OpenShift users. Specify OCP/OKD version 4.1 or later. The latest stable version is 4.15. + tag: 4.15 + # -- Image pull policy that applies to all user-deployed Longhorn components, such as Longhorn Manager, Longhorn driver, and Longhorn UI. + pullPolicy: IfNotPresent + +service: + ui: + # -- Service type for Longhorn UI. (Options: "ClusterIP", "NodePort", "LoadBalancer", "Rancher-Proxy") + type: ClusterIP + # -- NodePort port number for Longhorn UI. When unspecified, Longhorn selects a free port between 30000 and 32767. + nodePort: null + manager: + # -- Service type for Longhorn Manager. + type: ClusterIP + # -- NodePort port number for Longhorn Manager. When unspecified, Longhorn selects a free port between 30000 and 32767. + nodePort: "" + +persistence: + # -- Setting that allows you to specify the default Longhorn StorageClass. + defaultClass: true + # -- Filesystem type of the default Longhorn StorageClass. + defaultFsType: ext4 + # -- mkfs parameters of the default Longhorn StorageClass. + defaultMkfsParams: "" + # -- Replica count of the default Longhorn StorageClass. + defaultClassReplicaCount: 3 + # -- Data locality of the default Longhorn StorageClass. (Options: "disabled", "best-effort") + defaultDataLocality: disabled + # -- Reclaim policy that provides instructions for handling of a volume after its claim is released. (Options: "Retain", "Delete") + reclaimPolicy: Delete + # -- Setting that allows you to enable live migration of a Longhorn volume from one node to another. + migratable: false + # -- Set NFS mount options for Longhorn StorageClass for RWX volumes + nfsOptions: "" + recurringJobSelector: + # -- Setting that allows you to enable the recurring job selector for a Longhorn StorageClass. + enable: false + # -- Recurring job selector for a Longhorn StorageClass. Ensure that quotes are used correctly when specifying job parameters. (Example: `[{"name":"backup", "isGroup":true}]`) + jobList: [] + backingImage: + # -- Setting that allows you to use a backing image in a Longhorn StorageClass. + enable: false + # -- Backing image to be used for creating and restoring volumes in a Longhorn StorageClass. When no backing images are available, specify the data source type and parameters that Longhorn can use to create a backing image. + name: ~ + # -- Data source type of a backing image used in a Longhorn StorageClass. + # If the backing image exists in the cluster, Longhorn uses this setting to verify the image. + # If the backing image does not exist, Longhorn creates one using the specified data source type. + dataSourceType: ~ + # -- Data source parameters of a backing image used in a Longhorn StorageClass. + # You can specify a JSON string of a map. (Example: `'{\"url\":\"https://backing-image-example.s3-region.amazonaws.com/test-backing-image\"}'`) + dataSourceParameters: ~ + # -- Expected SHA-512 checksum of a backing image used in a Longhorn StorageClass. + expectedChecksum: ~ + defaultNodeSelector: + # -- Setting that allows you to enable the node selector for the default Longhorn StorageClass. + enable: false + # -- Node selector for the default Longhorn StorageClass. Longhorn uses only nodes with the specified tags for storing volume data. (Examples: "storage,fast") + selector: "" + # -- Setting that allows you to enable automatic snapshot removal during filesystem trim for a Longhorn StorageClass. (Options: "ignored", "enabled", "disabled") + removeSnapshotsDuringFilesystemTrim: ignored + +preUpgradeChecker: + # -- Setting that allows Longhorn to perform pre-upgrade checks. Disable this setting when installing Longhorn using Argo CD or other GitOps solutions. + jobEnabled: true + # -- Setting that allows Longhorn to perform upgrade version checks after starting the Longhorn Manager DaemonSet Pods. Disabling this setting also disables `preUpgradeChecker.jobEnabled`. Longhorn recommends keeping this setting enabled. + upgradeVersionCheck: true + +csi: + # -- kubelet root directory. When unspecified, Longhorn uses the default value. + kubeletRootDir: ~ + # -- Replica count of the CSI Attacher. When unspecified, Longhorn uses the default value ("3"). + attacherReplicaCount: ~ + # -- Replica count of the CSI Provisioner. When unspecified, Longhorn uses the default value ("3"). + provisionerReplicaCount: ~ + # -- Replica count of the CSI Resizer. When unspecified, Longhorn uses the default value ("3"). + resizerReplicaCount: ~ + # -- Replica count of the CSI Snapshotter. When unspecified, Longhorn uses the default value ("3"). + snapshotterReplicaCount: ~ + +defaultSettings: + # -- Endpoint used to access the backupstore. (Options: "NFS", "CIFS", "AWS", "GCP", "AZURE") + backupTarget: ~ + # -- Name of the Kubernetes secret associated with the backup target. + backupTargetCredentialSecret: ~ + # -- Setting that allows Longhorn to automatically attach a volume and create snapshots or backups when recurring jobs are run. + allowRecurringJobWhileVolumeDetached: ~ + # -- Setting that allows Longhorn to automatically create a default disk only on nodes with the label "node.longhorn.io/create-default-disk=true" (if no other disks exist). When this setting is disabled, Longhorn creates a default disk on each node that is added to the cluster. + createDefaultDiskLabeledNodes: ~ + # -- Default path for storing data on a host. The default value is "/var/lib/longhorn/". + defaultDataPath: ~ + # -- Default data locality. A Longhorn volume has data locality if a local replica of the volume exists on the same node as the pod that is using the volume. + defaultDataLocality: ~ + # -- Setting that allows scheduling on nodes with healthy replicas of the same volume. This setting is disabled by default. + replicaSoftAntiAffinity: ~ + # -- Setting that automatically rebalances replicas when an available node is discovered. + replicaAutoBalance: ~ + # -- Percentage of storage that can be allocated relative to hard drive capacity. The default value is "100". + storageOverProvisioningPercentage: ~ + # -- Percentage of minimum available disk capacity. When the minimum available capacity exceeds the total available capacity, the disk becomes unschedulable until more space is made available for use. The default value is "25". + storageMinimalAvailablePercentage: ~ + # -- Percentage of disk space that is not allocated to the default disk on each new Longhorn node. + storageReservedPercentageForDefaultDisk: ~ + # -- Upgrade Checker that periodically checks for new Longhorn versions. When a new version is available, a notification appears on the Longhorn UI. This setting is enabled by default + upgradeChecker: ~ + # -- Default number of replicas for volumes created using the Longhorn UI. For Kubernetes configuration, modify the `numberOfReplicas` field in the StorageClass. The default value is "3". + defaultReplicaCount: ~ + # -- Default Longhorn StorageClass. "storageClassName" is assigned to PVs and PVCs that are created for an existing Longhorn volume. "storageClassName" can also be used as a label, so it is possible to use a Longhorn StorageClass to bind a workload to an existing PV without creating a Kubernetes StorageClass object. The default value is "longhorn-static". + defaultLonghornStaticStorageClass: ~ + # -- Number of seconds that Longhorn waits before checking the backupstore for new backups. The default value is "300". When the value is "0", polling is disabled. + backupstorePollInterval: ~ + # -- Number of minutes that Longhorn keeps a failed backup resource. When the value is "0", automatic deletion is disabled. + failedBackupTTL: ~ + # -- Setting that restores recurring jobs from a backup volume on a backup target and creates recurring jobs if none exist during backup restoration. + restoreVolumeRecurringJobs: ~ + # -- Maximum number of successful recurring backup and snapshot jobs to be retained. When the value is "0", a history of successful recurring jobs is not retained. + recurringSuccessfulJobsHistoryLimit: ~ + # -- Maximum number of failed recurring backup and snapshot jobs to be retained. When the value is "0", a history of failed recurring jobs is not retained. + recurringFailedJobsHistoryLimit: ~ + # -- Maximum number of snapshots or backups to be retained. + recurringJobMaxRetention: ~ + # -- Maximum number of failed support bundles that can exist in the cluster. When the value is "0", Longhorn automatically purges all failed support bundles. + supportBundleFailedHistoryLimit: ~ + # -- Taint or toleration for system-managed Longhorn components. + # Specify values using a semicolon-separated list in `kubectl taint` syntax (Example: key1=value1:effect; key2=value2:effect). + taintToleration: ~ + # -- Node selector for system-managed Longhorn components. + systemManagedComponentsNodeSelector: ~ + # -- PriorityClass for system-managed Longhorn components. + # This setting can help prevent Longhorn components from being evicted under Node Pressure. + # Notice that this will be applied to Longhorn user-deployed components by default if there are no priority class values set yet, such as `longhornManager.priorityClass`. + priorityClass: &defaultPriorityClassNameRef "longhorn-critical" + # -- Setting that allows Longhorn to automatically salvage volumes when all replicas become faulty (for example, when the network connection is interrupted). Longhorn determines which replicas are usable and then uses these replicas for the volume. This setting is enabled by default. + autoSalvage: ~ + # -- Setting that allows Longhorn to automatically delete a workload pod that is managed by a controller (for example, daemonset) whenever a Longhorn volume is detached unexpectedly (for example, during Kubernetes upgrades). After deletion, the controller restarts the pod and then Kubernetes handles volume reattachment and remounting. + autoDeletePodWhenVolumeDetachedUnexpectedly: ~ + # -- Setting that prevents Longhorn Manager from scheduling replicas on a cordoned Kubernetes node. This setting is enabled by default. + disableSchedulingOnCordonedNode: ~ + # -- Setting that allows Longhorn to schedule new replicas of a volume to nodes in the same zone as existing healthy replicas. Nodes that do not belong to any zone are treated as existing in the zone that contains healthy replicas. When identifying zones, Longhorn relies on the label "topology.kubernetes.io/zone=" in the Kubernetes node object. + replicaZoneSoftAntiAffinity: ~ + # -- Setting that allows scheduling on disks with existing healthy replicas of the same volume. This setting is enabled by default. + replicaDiskSoftAntiAffinity: ~ + # -- Policy that defines the action Longhorn takes when a volume is stuck with a StatefulSet or Deployment pod on a node that failed. + nodeDownPodDeletionPolicy: ~ + # -- Policy that defines the action Longhorn takes when a node with the last healthy replica of a volume is drained. + nodeDrainPolicy: ~ + # -- Setting that allows automatic detaching of manually-attached volumes when a node is cordoned. + detachManuallyAttachedVolumesWhenCordoned: ~ + # -- Number of seconds that Longhorn waits before reusing existing data on a failed replica instead of creating a new replica of a degraded volume. + replicaReplenishmentWaitInterval: ~ + # -- Maximum number of replicas that can be concurrently rebuilt on each node. + concurrentReplicaRebuildPerNodeLimit: ~ + # -- Maximum number of volumes that can be concurrently restored on each node using a backup. When the value is "0", restoration of volumes using a backup is disabled. + concurrentVolumeBackupRestorePerNodeLimit: ~ + # -- Setting that disables the revision counter and thereby prevents Longhorn from tracking all write operations to a volume. When salvaging a volume, Longhorn uses properties of the "volume-head-xxx.img" file (the last file size and the last time the file was modified) to select the replica to be used for volume recovery. This setting applies only to volumes created using the Longhorn UI. + disableRevisionCounter: ~ + # -- Image pull policy for system-managed pods, such as Instance Manager, engine images, and CSI Driver. Changes to the image pull policy are applied only after the system-managed pods restart. + systemManagedPodsImagePullPolicy: ~ + # -- Setting that allows you to create and attach a volume without having all replicas scheduled at the time of creation. + allowVolumeCreationWithDegradedAvailability: ~ + # -- Setting that allows Longhorn to automatically clean up the system-generated snapshot after replica rebuilding is completed. + autoCleanupSystemGeneratedSnapshot: ~ + # -- Setting that allows Longhorn to automatically clean up the snapshot generated by a recurring backup job. + autoCleanupRecurringJobBackupSnapshot: ~ + # -- Maximum number of engines that are allowed to concurrently upgrade on each node after Longhorn Manager is upgraded. When the value is "0", Longhorn does not automatically upgrade volume engines to the new default engine image version. + concurrentAutomaticEngineUpgradePerNodeLimit: ~ + # -- Number of minutes that Longhorn waits before cleaning up the backing image file when no replicas in the disk are using it. + backingImageCleanupWaitInterval: ~ + # -- Number of seconds that Longhorn waits before downloading a backing image file again when the status of all image disk files changes to "failed" or "unknown". + backingImageRecoveryWaitInterval: ~ + # -- Percentage of the total allocatable CPU resources on each node to be reserved for each instance manager pod when the V1 Data Engine is enabled. The default value is "12". + guaranteedInstanceManagerCPU: ~ + # -- Setting that notifies Longhorn that the cluster is using the Kubernetes Cluster Autoscaler. + kubernetesClusterAutoscalerEnabled: ~ + # -- Setting that allows Longhorn to automatically delete an orphaned resource and the corresponding data (for example, stale replicas). Orphaned resources on failed or unknown nodes are not automatically cleaned up. + orphanAutoDeletion: ~ + # -- Storage network for in-cluster traffic. When unspecified, Longhorn uses the Kubernetes cluster network. + storageNetwork: ~ + # -- Flag that prevents accidental uninstallation of Longhorn. + deletingConfirmationFlag: ~ + # -- Timeout between the Longhorn Engine and replicas. Specify a value between "8" and "30" seconds. The default value is "8". + engineReplicaTimeout: ~ + # -- Setting that allows you to enable and disable snapshot hashing and data integrity checks. + snapshotDataIntegrity: ~ + # -- Setting that allows disabling of snapshot hashing after snapshot creation to minimize impact on system performance. + snapshotDataIntegrityImmediateCheckAfterSnapshotCreation: ~ + # -- Setting that defines when Longhorn checks the integrity of data in snapshot disk files. You must use the Unix cron expression format. + snapshotDataIntegrityCronjob: ~ + # -- Setting that allows Longhorn to automatically mark the latest snapshot and its parent files as removed during a filesystem trim. Longhorn does not remove snapshots containing multiple child files. + removeSnapshotsDuringFilesystemTrim: ~ + # -- Setting that allows fast rebuilding of replicas using the checksum of snapshot disk files. Before enabling this setting, you must set the snapshot-data-integrity value to "enable" or "fast-check". + fastReplicaRebuildEnabled: ~ + # -- Number of seconds that an HTTP client waits for a response from a File Sync server before considering the connection to have failed. + replicaFileSyncHttpClientTimeout: ~ + # -- Log levels that indicate the type and severity of logs in Longhorn Manager. The default value is "Info". (Options: "Panic", "Fatal", "Error", "Warn", "Info", "Debug", "Trace") + logLevel: ~ + # -- Setting that allows you to specify a backup compression method. + backupCompressionMethod: ~ + # -- Maximum number of worker threads that can concurrently run for each backup. + backupConcurrentLimit: ~ + # -- Maximum number of worker threads that can concurrently run for each restore operation. + restoreConcurrentLimit: ~ + # -- Setting that allows you to enable the V1 Data Engine. + v1DataEngine: ~ + # -- Setting that allows you to enable the V2 Data Engine, which is based on the Storage Performance Development Kit (SPDK). The V2 Data Engine is a preview feature and should not be used in production environments. + v2DataEngine: ~ + # -- Setting that allows you to configure maximum huge page size (in MiB) for the V2 Data Engine. + v2DataEngineHugepageLimit: ~ + # -- Setting that allows rebuilding of offline replicas for volumes using the V2 Data Engine. + offlineReplicaRebuilding: ~ + # -- Number of millicpus on each node to be reserved for each Instance Manager pod when the V2 Data Engine is enabled. The default value is "1250". + v2DataEngineGuaranteedInstanceManagerCPU: ~ + # -- Setting that allows scheduling of empty node selector volumes to any node. + allowEmptyNodeSelectorVolume: ~ + # -- Setting that allows scheduling of empty disk selector volumes to any disk. + allowEmptyDiskSelectorVolume: ~ + # -- Setting that allows Longhorn to periodically collect anonymous usage data for product improvement purposes. Longhorn sends collected data to the [Upgrade Responder](https://github.com/longhorn/upgrade-responder) server, which is the data source of the Longhorn Public Metrics Dashboard (https://metrics.longhorn.io). The Upgrade Responder server does not store data that can be used to identify clients, including IP addresses. + allowCollectingLonghornUsageMetrics: ~ + # -- Setting that temporarily prevents all attempts to purge volume snapshots. + disableSnapshotPurge: ~ + # -- Maximum snapshot count for a volume. The value should be between 2 to 250 + snapshotMaxCount: ~ + +privateRegistry: + # -- Setting that allows you to create a private registry secret. + createSecret: ~ + # -- URL of a private registry. When unspecified, Longhorn uses the default system registry. + registryUrl: ~ + # -- User account used for authenticating with a private registry. + registryUser: ~ + # -- Password for authenticating with a private registry. + registryPasswd: ~ + # -- Kubernetes secret that allows you to pull images from a private registry. This setting applies only when creation of private registry secrets is enabled. You must include the private registry name in the secret name. + registrySecret: ~ + +longhornManager: + log: + # -- Format of Longhorn Manager logs. (Options: "plain", "json") + format: plain + # -- PriorityClass for Longhorn Manager. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn Manager on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn Manager DaemonSet, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn Manager. Specify the nodes allowed to run Longhorn Manager. + nodeSelector: {} + ## If you want to set node selector for Longhorn Manager DaemonSet, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + # -- Annotation for the Longhorn Manager service. + serviceAnnotations: {} + ## If you want to set annotations for the Longhorn Manager service, delete the `{}` in the line above + ## and uncomment this example block + # annotation-key1: "annotation-value1" + # annotation-key2: "annotation-value2" + +longhornDriver: + # -- PriorityClass for Longhorn Driver. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn Driver on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn Driver Deployer Deployment, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn Driver. Specify the nodes allowed to run Longhorn Driver. + nodeSelector: {} + ## If you want to set node selector for Longhorn Driver Deployer Deployment, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + +longhornUI: + # -- Replica count for Longhorn UI. + replicas: 2 + # -- PriorityClass for Longhorn UI. + priorityClass: *defaultPriorityClassNameRef + # -- Toleration for Longhorn UI on nodes allowed to run Longhorn components. + tolerations: [] + ## If you want to set tolerations for Longhorn UI Deployment, delete the `[]` in the line above + ## and uncomment this example block + # - key: "key" + # operator: "Equal" + # value: "value" + # effect: "NoSchedule" + # -- Node selector for Longhorn UI. Specify the nodes allowed to run Longhorn UI. + nodeSelector: {} + ## If you want to set node selector for Longhorn UI Deployment, delete the `{}` in the line above + ## and uncomment this example block + # label-key1: "label-value1" + # label-key2: "label-value2" + +ingress: + # -- Setting that allows Longhorn to generate ingress records for the Longhorn UI service. + enabled: false + + # -- IngressClass resource that contains ingress configuration, including the name of the Ingress controller. + # ingressClassName can replace the kubernetes.io/ingress.class annotation used in earlier Kubernetes releases. + ingressClassName: ~ + + # -- Hostname of the Layer 7 load balancer. + host: sslip.io + + # -- Setting that allows you to enable TLS on ingress records. + tls: false + + # -- Setting that allows you to enable secure connections to the Longhorn UI service via port 443. + secureBackends: false + + # -- TLS secret that contains the private key and certificate to be used for TLS. This setting applies only when TLS is enabled on ingress records. + tlsSecret: longhorn.local-tls + + # -- Default ingress path. You can access the Longhorn UI by following the full ingress path {{host}}+{{path}}. + path: / + + ## If you're using kube-lego, you will want to add: + ## kubernetes.io/tls-acme: true + ## + ## For a full list of possible ingress annotations, please see + ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/annotations.md + ## + ## If tls is set to true, annotation ingress.kubernetes.io/secure-backends: "true" will automatically be set + # -- Ingress annotations in the form of key-value pairs. + annotations: + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: true + + # -- Secret that contains a TLS private key and certificate. Use secrets if you want to use your own certificates to secure ingresses. + secrets: + ## If you're providing your own certificates, please use this to add the certificates as secrets + ## key and certificate should start with -----BEGIN CERTIFICATE----- or + ## -----BEGIN RSA PRIVATE KEY----- + ## + ## name should line up with a tlsSecret set further up + ## If you're using kube-lego, this is unneeded, as it will create the secret for you if it is not set + ## + ## It is also possible to create and manage the certificates outside of this helm chart + ## Please see README.md for more information + # - name: longhorn.local-tls + # key: + # certificate: + +# -- Setting that allows you to enable pod security policies (PSPs) that allow privileged Longhorn pods to start. This setting applies only to clusters running Kubernetes 1.25 and earlier, and with the built-in Pod Security admission controller enabled. +enablePSP: false + +# -- Specify override namespace, specifically this is useful for using longhorn as sub-chart and its release namespace is not the `longhorn-system`. +namespaceOverride: "" + +# -- Annotation for the Longhorn Manager DaemonSet pods. This setting is optional. +annotations: {} + +serviceAccount: + # -- Annotations to add to the service account + annotations: {} + +metrics: + serviceMonitor: + # -- Setting that allows the creation of a Prometheus ServiceMonitor resource for Longhorn Manager components. + enabled: false + # -- Additional labels for the Prometheus ServiceMonitor resource. + additionalLabels: {} + # -- Annotations for the Prometheus ServiceMonitor resource. + annotations: {} + # -- Interval at which Prometheus scrapes the metrics from the target. + interval: "" + # -- Timeout after which Prometheus considers the scrape to be failed. + scrapeTimeout: "" + # -- Configures the relabeling rules to apply the target’s metadata labels. See the [Prometheus Operator + # documentation](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.Endpoint) for + # formatting details. + relabelings: [] + # -- Configures the relabeling rules to apply to the samples before ingestion. See the [Prometheus Operator + # documentation](https://prometheus-operator.dev/docs/api-reference/api/#monitoring.coreos.com/v1.Endpoint) for + # formatting details. + metricRelabelings: [] + +## openshift settings +openshift: + # -- Setting that allows Longhorn to integrate with OpenShift. + enabled: false + ui: + # -- Route for connections between Longhorn and the OpenShift web console. + route: "longhorn-ui" + # -- Port for accessing the OpenShift web console. + port: 443 + # -- Port for proxy that provides access to the OpenShift web console. + proxy: 8443 + +# -- Setting that allows Longhorn to generate code coverage profiles. +enableGoCoverDir: false diff --git a/index.yaml b/index.yaml index 78350f8ccb..c0a2fd97b7 100755 --- a/index.yaml +++ b/index.yaml @@ -4683,6 +4683,49 @@ entries: urls: - assets/longhorn/longhorn-105.0.1+up1.6.4.tgz version: 105.0.1+up1.6.4 + - annotations: + catalog.cattle.io/auto-install: longhorn-crd=match + catalog.cattle.io/certified: rancher + catalog.cattle.io/display-name: Longhorn + catalog.cattle.io/kube-version: '>= 1.23.0-0' + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/permits-os: linux,windows + catalog.cattle.io/provides-gvr: longhorn.io/v1beta1 + catalog.cattle.io/rancher-version: '>= 2.10.0-0 < 2.11.0-0' + catalog.cattle.io/release-name: longhorn + catalog.cattle.io/type: cluster-tool + catalog.cattle.io/upstream-version: 1.6.3 + apiVersion: v1 + appVersion: v1.6.3 + created: "2025-03-02T13:05:40.159541607-03:00" + description: Longhorn is a distributed block storage system for Kubernetes. + digest: f914d102b0b0dc0e422d45bbd664a18327db4f2d49436bfe5cc1c62a29dad5c8 + home: https://github.com/longhorn/longhorn + icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/longhorn/icon/color/longhorn-icon-color.png + keywords: + - longhorn + - storage + - distributed + - block + - device + - iscsi + - nfs + maintainers: + - email: maintainers@longhorn.io + name: Longhorn maintainers + name: longhorn + sources: + - https://github.com/longhorn/longhorn + - https://github.com/longhorn/longhorn-engine + - https://github.com/longhorn/longhorn-instance-manager + - https://github.com/longhorn/longhorn-share-manager + - https://github.com/longhorn/longhorn-manager + - https://github.com/longhorn/longhorn-ui + - https://github.com/longhorn/longhorn-tests + - https://github.com/longhorn/backing-image-manager + urls: + - assets/longhorn/longhorn-105.0.0+up1.6.3.tgz + version: 105.0.0+up1.6.3 - annotations: catalog.cattle.io/auto-install: longhorn-crd=match catalog.cattle.io/certified: rancher diff --git a/release.yaml b/release.yaml index 0ec067e4b0..dcf2e5b980 100644 --- a/release.yaml +++ b/release.yaml @@ -2,3 +2,4 @@ longhorn: - 105.1.1+up1.7.3 - 105.1.0+up1.7.2 - 105.0.1+up1.6.4 + - 105.0.0+up1.6.3 From b45a28c33ba549d3fcfddbb59b9d4774f4217cbb Mon Sep 17 00:00:00 2001 From: nicholasSUSE Date: Sun, 2 Mar 2025 13:05:50 -0300 Subject: [PATCH 6/9] fp: longhorn-crd-105.1.1+up1.7.3 --- .../longhorn-crd-105.1.1+up1.7.3.tgz | Bin 0 -> 13408 bytes .../longhorn-crd/105.1.1+up1.7.3/Chart.yaml | 11 + charts/longhorn-crd/105.1.1+up1.7.3/README.md | 2 + .../105.1.1+up1.7.3/templates/_helpers.tpl | 66 + .../105.1.1+up1.7.3/templates/crds.yaml | 4400 +++++++++++++++++ index.yaml | 15 + release.yaml | 2 + 7 files changed, 4496 insertions(+) create mode 100644 assets/longhorn-crd/longhorn-crd-105.1.1+up1.7.3.tgz create mode 100644 charts/longhorn-crd/105.1.1+up1.7.3/Chart.yaml create mode 100644 charts/longhorn-crd/105.1.1+up1.7.3/README.md create mode 100644 charts/longhorn-crd/105.1.1+up1.7.3/templates/_helpers.tpl create mode 100644 charts/longhorn-crd/105.1.1+up1.7.3/templates/crds.yaml diff --git a/assets/longhorn-crd/longhorn-crd-105.1.1+up1.7.3.tgz b/assets/longhorn-crd/longhorn-crd-105.1.1+up1.7.3.tgz new file mode 100644 index 0000000000000000000000000000000000000000..3fddc48c2271d0eb74c74cc22b3062d93b32f69d GIT binary patch literal 13408 zcmV-mG@r{KiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMYObKEwTD4fs!6)5d9Wqa1$k|uWYtg5DV70JG%UCVJvwo`Ry zQwf?xcOzm09DrRAo&mjBeXydV(liQOA5<)YWVM_SP696KZ!GtcR5zMj#O)));5XI?|DLC6sE1y`&7Ru%&(JDOV21eNFH4l9i1BHbZcYn&&i}XHAAi?4 z|KA;d|0q?*{TA~y1=fgk#cp|=f^7?ZMNh}YM zI5B|E<=>HH8c+0h6A+_0CI}pq=SzHi04CLIm?s&SDrWOe^fdhhlN@pR<&SH`7>*J6 zC&*Y%BJka}@=v_F&gXOd85~Ti&Jc;^-wMDphG2#OEXSDVNpc7Nk;6n%FmawG=+h@Z zA=SJ5J`-bzX>c$@5zILPoURb~pL~WGK^fv|!gGw0m;=ZVNbm}0C9NW}NG;fVEq^d5448-ss>*>^7yiJq5#0b|B$*H6IVpP!V-PT&kB94rt) zOptN8C3yx(3|S2RhLROfpNMT~p2+$#t8Wy7VVX{F%5zY#@e}a-@1Woot)o5_z%5a- zn)2nLBoFd?b2I<($E5m2GjH%uz)+gN2!VrtKL7{6$i-^|pmt$Ancb;wi@ko0*cwO3 z-UtgBfJCU?M8jhFzGU|mn5U(f0lIgdlxcp^XZV+5RjUn)=j9eyBy zTUgHc;lZd5P{J#UanL?M4T@ULsF=bpIZLe5=sF^u;16kNfDK9l<3#ebxj3y^9sc=A zF*9*Kip>kOzzIq@)pkhqN57OGS@BW6Z4v7JFKVk)+o|&V&QuH_u+)rJD1$M~pwJ&1>LdUWB^jehg4kq%h$OPJ949eiH7dJ4njXKJ9z6k?K?%A$ z0c~-jU`( zCcs`Wnx~aUC|;><^rRF*eo#GLh#t>j2Crq03KGn-|LOSXE#{g0Fimm>6DM@?8@{A0 zdsmG<0m*WPWBn47MV>(B>f#9iJfcFGEh$L+1OSbA+2aJjIF?HZllOv1BX&lUd_~If zYTEP%A@k>q3DomU@PDlcq%;OOS3+^h=o(8_Dc)$%fP_u7qWlxL9cQdVM@Y89Y`eAX=goJkg)i6p_>S7oWbpuKf(^ z7_py9fH}BbB8I@*LMGrDWr#aAFsN-PI{OVp*|dC{GMXZm;o{h;$Dp^yuMP12IjOw^ zK+H&so=Ol=qP;%FDAq_&ClPZYM>E6`QKVS>3`q+>^$4jMF)pY~p2UJ)uMx`tLlIpN z{H5%hD_s`>DIjD((g^|+uoeQ%3jj&n=y?V207GI-kQ1Z7wUU4uUtdy&048&K0)$$~ zPYw?kI4ihNL|3bv;Oy>DG88<^Gs^g3jMgYQI|$)g$S<$MOhLFE$UZ~V(FUQo=HwEPJNz=!xc9_xFFyRu26C& zq|f_ZE3qnkA{JrLYMJs!^J9fx<3+*ZtLO8i()=cJ71$b0a&klHEtx2r&k4v_ZXSHa znKtgI1*B{f8(#?m1Q+N8%wfXyPx-9e%>@J+9`O4g;~2V9r%KB~3SgsfBo=C5mo%zH0vN#D|;|<~Ne!`Zf}T+^dn` zARibce2y4Hv8(Nj(gZ=$c&qrD*LW#paD_6&T8IKQNzR4Np6;C+M?94v((V-z+Y(Jc zOm9g-VUswDS9$7qfj*~{WfO76Cu<>$HaC~}h#|?GEN`NOlJ@T%lNREq$0E3nmPO1T za=2u(+VP?@CEAzgs{xz%=3&p5DFS;n#HrWkE5y0bXnfkxTY{MHsbX}&5VxEb)ktvr zg^Xr0AC?n>$>RO4k0i;H1kMuF(k#uk_7jW0SdcfTYy~qptM6WV%~)%g7wqCJLa`%2~YQT^xbfq@IV~=$sSi-^8wWuS8C3gv&q1{hs{J0Q_Q6{bn0;XO`@-zE zW6lrEJ}~>@3C#X0V)lI$VT(rmHqq!ZFwP8E9>8dQf35(D9IqDM_Wx~|o{Rl3!0x=O zEdf(}iHVhgfF28^i}CceGk4(|oS;i+u|yBui|(1JM~jbVPSd&xuVYJtF7x-m_ENkU z+t_UrH#@LnTRj|+7%{!yPUE=0w+?VbXP7Lm&>S&DqMmtmf@L*|tEbyEK6nJXUu57+ z?e3_7jn|lEIZUp1JjV`#yNSQzzWhpKd_=+b@d$k%cBhAu{wpTIGX^uXxH|zqq1lqs z8~N+4`ny1<5<1T)nd3#Z#9So`nrq%H0Z>fI z4|S)9)i~y7lw~L2KVBUj7qck8x}=pq!!ESBs9zqccJ$Hqg zi{*4MmwSlv2bcf^qop)&IFYbv$iLP=)QB1t3Xo^wtj`3cWea)UA*q0S?gYqCX=-qN zYW==%#`?g50}Bo;_&(R_k=W!18RJW$&_IzZ8)qj`^lxw?q1~yy6s>WTNtIP@Dq9%6 z39LPs9`u=|dYlB;C_zz1S$k}pq19NQ1Y``}Sw`EHC#1IJ&c)G>x{c> zk%Y$R{uWNv3G=fW$|j|`!mq6)<~t8B|LQV6w&6t^>OLDp#P!hkLd)eyJEi6cE)=lg>i_f*1uk$#4RsfdxE6)5TPDoFD)jbOUou zQ!!aQ-x}hA*J?*zt32)ZT@81_`8v zZ{cZ-8EvO^GU`Jq-0GtZ#75^!6oU-+Og>LlS>yOLYt6s?ZZurn2!ghtV&kA`AwU3r zN20ztOG!h1*O>6z_KViQ+cW3Y&)HC;oU$FA+p_Q*r54LCPYm`DIDV`6&vK0FjDPO|OiCS|}Rfz_e%EUYr9;wEa&?(xu_4nGKs!%PfR?Ln54@f~9+{o7==aj9C=zU4uHR z0ri_n?Pe7BIUG}x$ZDJKm!6!+D8hqO*EYfF3=*OE92~p=2N&eMMxOYe;719{P%QrQ zTI_D|$43<_ci^?AIZMVa=f|tJ9zz9l@6OD4H;vAIjbhoc$v#~=QX}xukdCbQ}3|!F=x}qH`&-bTX0M6p@(qb0ot!a z|ImKHnkTU7_p>14Aw7YQz^xX+BoX_uyuuuj1tv0oOMBcb!?t~Jd1`SIjo%6c-6nS* zB~6f5qV#)|u5}{&>@GucqslHcT|u##Vm}Cd59;RAdvbT)z9#t{=jdbTqek!8MPg|5 z0x^^(ID(_y=(@e(INyXE5A=D~Y$SdIG))vfqt$FAqlVqRoVKaIcHca-%_HdNoCQGT zLzqUykFmSbl%fR-79cpm29Sl^jrT}g4F`rm_8 z|I5=468&ni8nFrLl_NqyFPmBxTbzPE5{*EGtQc-b`DLYAAc(U@O|w4J%$QyEl`a!i z{@=sGuSbj+61yM6MAr&%j9-0sZGNTzI4fU{h9jj(qHNadvX>?d;+u>5CzY>3E&pJb z$_0sW1T(2DXG>|dZGwb3fNO}QY9Uk+LT$)VZjkcB8eFH1U)zE0y?EKbn1>G~_B!1$ zdVawx(^S@jS0;F69=}&61V9Al9hmo{W8RxaQ3U24nD?ON3Cw$snYZ)cZ=5V%(uUf* zK96q683$&Z)OfC+`?kRey$5WuTtC-|!2|~kU9i;3^B5&L&kzFyp;(fqGHT!!mzM_C zfN9R)(L^;ofGc#f;0Ap}worM`_mq?ZO3wn6A`8G;LgE0=ov5z~NtV5%#3t8Wm4GhF$H$L7;ym_#Z+Bqy$ZFDT`lJ zqC>Hr=akjgV65(>Sb7r|PpHYrPx2^nQL|0zq$t2L1wQ59jEK zW!56FmT7&sOHl#2Xfzn^ofp!ymGs>_7RiVJ*@sx9#}MzLxr$fVOK_&{%$cgZ+neVq zf2t}sH@$-DmBTBj$5*Rk^9rujtAh;$4YBNxJ?P(30;%H-|1B|`$$*KL{Yu3~A3ue7w)(d96{WI$YpIl&_fpu=# zBNkX^V4Z`OC$P>vW}VK1zYUL=allF~wQE794a)N=JRrSwf>55Ye3YIWzA!m9;7Nh_Sbw z#af7CgDl6AVHYT@1VK*}n!@PVVZAq~81|CJcrM*SF6UU^UX{reN&;OOojI_uOC$K! zGLZGuj6`HitcGwScHryGJ$5A?TL!GMj_YXN>hXOHeh|HTJkx(Y%I;QU_~)T2Yr$Cp zIUhi4l%G;I0g-4UiHwj7()D4wj=&6)Sg^>_Ipz|Df(Ph6JwWO(cHBo6vgvl1P4`-2 z-*$hS@uuZ9GuKS5iN$G#nisYit)2+MTNxE~Sil=?QY=h^TXv~kn@WPF|K>$3yC|gh zw!v>)T@weS(TeLBb2& zve|hPPag4|6Dl|;yhJcFyW*5&EK(b;yqZN{;2TMSK%1cPBP7zTsk z9vTe4dSBZaU8OL?Go0Y;&WqS%66v;$jH`?Gi{7NGz}f?A_h9Ygy@7$X2i87#c>-(S zW7h6E_8YkZEwoZSZWk1`U--Df#;L2wV}gq1hPst(?(dA z=PSXd?=LPfv65iWQ0sf%>+U=)81t>Rc?h%sH)k?s2&9Ge%39n&f_UcWVS6o&08;n}@4f(!9JU5J~ck15GjjnwdfIhhC=ODi%PSgM1d?!q;s0NL^vQrm|opYxEq9WWh+b2S&25-v1>Cyue>c z$a=`T;Bn&n*X9R`)SioOYQOt%m%!cwdw(c*SYYpgy$AMwFKhMSJ}}QqH*17YJskz^ zq71J+jb1Yt-5?UnB%*VM*QoEJymPUgB6*9<6-pDKWP{lqkRk^7wc^dcdZ%j@iE3Wv zqiVo*GuJJj>$b;l0@i==8dk2_wYRk^#vINP^oCKAp(Z5&J!^$3-(b%oJvCMdSe8jL z+h3TvmXr4rFanJwyTG!_z>r)AZ= z3vCMqV~2mD!ywFx$*MH8D>R@$1u2KA&jKEQzE*Oka zeD(0#uIo;)E*C+^Eng#%yjggL{{_8Xe0*ly0z7_^`r;haDAsb(J;*B_$Gy4(Te~m7 zG&``LJ@xcmDmf64?pqUwc48L=2DRSYjcjcjCA8S8yW2&Z?E#@`Ty19+F+WQv!DP|h zgUh)Jwz4DtWw%lYwCVvU1X_has}N|lXMt9R8QCx3RW-aXiFyONtvwan)lW?ShZo)o zgQ90ZSIhO_*WR)$U7z#UpHnEy9Qf&3f{MtdLaTjk7mK<~5N7i?5GVGsCOti9O*b0+E7h?=XnRb^7Z9wB^dYz(37RLP>f=RZ#JI$WE zTvd)uB3bO?H_w$)s(=@hg-a$F*xiQo6(@*nVigfoRZnC*Q8h)R2Q*whLdvW?DX%}H zDF2snq!c~x@R&wRoWu+{?G{7FG3U~?gL~K5?8vc8Kvk`D^dWGS0aeeKS$7P!tx0c0 zfKn)^>FDN6x$wr*E_=nmfurXfu|Z4jhG18Or#PejDl^X@^QToRsP*E#*HGJZ$y$-& z5se%2mn`{9g_TIZ+a!_67Ry>?G&SC~Qk$B9sFkwhIN_CgRVFz#T0Tg&Q_Xwbj1|^f zY=;5Srp>q&sr;;nhAn0J=N5>BbT7K8!SSK`!9Om$1qkMV<%9^0XM2&_k1qA7vC-W@ z%I%Qy5UyPBIfN^RaOFJ+R}R@o_H3j9d~oY|Nr4gni!tKyNkV}U2Sywi@z=zNyN>@x z_46EzL_Ka(XIGL1#JSmZ+Gb+Lt@D@VAfW@U~!JhF$e+E7z`i23Xg-Pq=4ST}JkSo%9;= zyCW@!tV&lzbM^T7F~C3%4jAgt07GyAIs@yP9rY}pbn;$ur;BxPM+xSc+bcG>o0PKb zwJqncdJOO2x9uFx=6GFh*XiYl)b<2 zg{p?V=jG}Oh6Y=qZ#(j|6&zDX?*x|Vd;-g~J%MG~I|?i_u*^m`fn~P8+Gmy-c%}0R zywdgrUTN}e=F3>c5$f<_^@9ph$x5UP(NmQY+MD=>V@vs-F z5(WadOC;0OvLYfyhBLsps3%~F!zsnTzdyYaUq1c$?@!gcr$0Y2H_DaKPhUig6`-6W zR+JTt50MH-FOvazv_x^9V6qTwsv<6WCYA}LD4N0~p|{s%(;C31)^}~Wv=8<&cqM|Q z0238(b3jQKkZmk$h{WujxHi6VWBk#@;l9&5&K~nq{$Fm)5b)FJIRyNKfS)}G`1$H1 zZ@0s1|MS^@$&k~({#A3`=RZ$tMYjUa-6GF5ux)Z*JI)`H_l^&}4ZJt--T})Kc<&zb z-qwNlEYWX}OZ9ZbSJvsc%SL23@5h+m?9dO@3tK;g6`b9UD0^_OdaSkHi&rqu+Tpw9 zOG{|433G?ZRDk@U!|vJ*@Ej+I-|-BsoS(=__+z0%YaC_LWaF%IZuZn!R7x<{v2bWH z@Cs=G(b3NkCqlm|JcA3TE6iDOcHl&cPi!?IL7#!VRO^kp~JKHA9Y85hG@Hk zv@3$%ifSj4JJIVx?AW+?Nsqm&t^1JVJfpAWy7|)MP!qWipimPz)I<(7k@u@6vJi!K zUD~ccIHrfg4~f7TNK4hT9g3=+K~W7p)U^}D9va)(B`_%P07~mMy&kG-nbTm}+cPIg znTOIZuQ_#7W6P9=)8w8x85DabGwY_(mYH?XYV~YLvDGtzZhK9;FV<#Tl-vWT0r7Yq zweVaT&JZnqkk-7>MJJ+z_nT;>eR}(#4nBUgMG6hR8vsGVXG;9fi#^wCD(d>nzoJ zwnULr0PU9hq`Ze1rZJ9WH})G8fPuRhW@sYhD7T2;ZRxO1{|oghln}!Ib`btYS-ON| zlQNJ$${y56Wh|Teu@%jxM^md{iDy%m=_;O$7Jcuagrg~$&}t5CkF$FDVXGyYRG-_t z!+txC+#gH0?5 zVXe&{=y;<8FIZE^;0k4kZD5z|l;>K@RE=nz;c$U)tnW+jV{h-*=36mm}o6WYb zxL>1;t9fIxDAhEHA@I`@5x|kWJ-2@7EF?w*QLp&5_&HI zgz6jDexoz}JNk^JCaAx5DD85zdPMjCF@Nf_6kIFKbcQ5nq;qhf?l(ICl!1f7_;=tK zJ%jwFZlkDv7-FM{7$pFG7V4SQzbj3xT2_e?-i)ztLLz#qL2_38FvwbxuV#n|1eEvQ z94bu6MZZBPEqPhzf-u3X>!4hjKea8tHoQ=x>u<{0XB4oUfY}{DFj^|C{iY9>1r}nO5&&lpyuFmX*rC>itO( zstQDyWDKu@Bo!p7J&~lwJN1Gj6(p%3NqrrXl=I+kbRSBMHq_pAI!6ksJiys!d@W&t zH^nw9*p}v6E^nCQ+6-p1o!i+pN152$UhXy}7Y!JpPF-cQ_CVXsC39asy&FfMk|*^> z8n|j!+qFG2uLq@~(IfVhI$gtU_h~Qc0JzT6l(Nj612~xHNixxbujFTIm^husj(9{N z&kaJo_z*-iCz-#|T)a6wlsdsEy->4qf4NS#w9j|J`b$zF2(e;U% zl;sOGGv|vw7#i~*en7`Y1JrolhSx)lVSDH^igE$UnK&Fn!dyxPO{n`SL~se$2+R;7 zAY*v3K&&m%be|`u53e=6{1RN8>lm9>P)#$0ro@TmjEVE-6c#xV zZ%ommG3Gh;vVXO&SRICFOM*`gjK=+c9uO7lE-zd3T=xsnrVfYki)HjjR~+-IT6LH8 zM|}|NKEdu2>^}Qv_xb8QXpTGS-4uT7SJ4N_B1jhdDp_peTnds!kSu~^agS^DpdKZ8 zm_3umY}dngl$wh&ymlsr+l$N%x!rABce-^L{RJ49EH1n+^cMr3V}_!PvO9ZOi=Ni5 zYvWw@<@K@c$M(HUUBk*n_rH=}2?5?s>?Ke-8YxN8u^7WHaMJrhvi4u6?W>x4NB3UK z4U1#WAx`Y|9QvIpZ**HhsyWJ3$QT4HCqz)_f|1W<_7i2z_ge7A9OSanyI_bpN8*d3 zC1n7TJDrSV^U_ox=$h<0X{N{}6JzHL0UAjGD%R0)4ai>@V`2^xe1noZ0gkk*=N!%R z#4`A^Y)SLQ5~P%KJWK8bHA~QQm8c0$%PwzmwycH}m|Epr@(LzRzM0}a5D-cxYC+1j z&nN>p1Ch1x>`Vd|11!+WVX~H)XLA6Pq^dp-8Pco#d|I1$lprW*@C?lb|A88sSS*$9 z%xJK(7Cf3M`9&~MNOX=8Qx1Vxt#QWgBz#1#_tR3st0xLx!W7I<1jP=(^)1y3H8US0 z!52nC=}b_((AywdLbCAl@-88Zg;sMqmsWgBC_-0b1e0ueH|{k3t!P}#UG87Ziqyzz zi_TC)S4iF8aCpmbhH4lFa4uG)kn+WH>Xn^VgIEA?93h$3$MYycoX_*5+9mZP)dauu zOj$-(r>y5p)dq3xU-L5|<+b*xbr;3eGGJrnARhl4kzY2ogH?Y`QFp*cNh#jVnzPzy!6UE0C5R)nR8@&}XdePV?wQ0W4 zG+y)+(N!w)IF);m5iv02h)>&7 z`U(z9Vxn;D-fvNBv7C3Fl)5|(Wp6K9om9-ePk)vs4axmimq@R zC*?>5arQe8*8NwWkopGR%5i8i4+{YQS|U$E7bBGiS80}x!Spt`LK(YrM7(sxsW7z0 zya<*->|Ea!pSa^1K`N0m%=41uaOUQ1{F~2!mLQJmE zimp-onvB4a+I-&HsA{&=nT-$ZQl_VkW4e57QK7<1A3&kPOQ`S?D!lAhg%{KL=*139 zZ}qmVnqCH3=}c~Q>bB4hx=F~JJ9=KXpU}k{ltoKl-aYD?e#(3$86`!%mhsEpLR1FX zh(~yn6yn zV)lsQJ9k8hTjTJG62df1a9Ja^9miLHujzE{x3&cI2&4D{?GLm+(EfW}tDQ#i^%+w? zv@9&v>IWS`dWyykNHA>^Qk%^ouv z=fU5oYNL%AsHJ5)c~DaklGPx+7T`=yk6K2Zsn`jg&@$$_!VMk`V%W#K|8BOf*@SVDK1dj+)Y>jVAB>mXk>f3`XHni0!I z(SMaaLGUVH0gk^&8l=~_upujumv=D}G)l-;6;UyFKnL7%zSsCm6Y%EmLo_fLWjRbr zU`>R(^}goN-D5sJmCM*sV#4aC`{cN;;uO4n3T?JpbTXT%l{zH zos2Wb9N^U|&t#%VJq_R1@=CMv;W~uNy=~FpMk~O@Rv)7Lj^6D{6y0!JrJ1g5f+bF3 zhAgQsetXq^4mR0%rWE3r=fD`XlpgBLUf$tx9gl$(WH&nB@E(#CAVcoNOGn;mA&vWi zX9&sTG8!Gp6I<>t=ZHxi$q)U(B(V#Vgt}~FmXkO^8`&jPM?c7pn#Kw9UE4xY1Hoyg zm{mO+h6=OoeZ->ZyGaaScH<+&oaYF9yn5>}gvj^RYh7Mb{5WusQ!rx~&CMT+Nn)d$ zR*lo@^V-not>5=TCpI@`haa-G>P-?9bmX8T2OW9ebY%17Z{&z?nH`PL zM{C<^Lyzp3ofT?&^Z^uVdW4!Dp{B=!)bwx{?U>^P*>A?|7*9rvY}qz3Bt+;#OA)Nc z3;E1JH?)Gm;B}gxJPWb}JJBxeL^3K%->tui znMn5YLlw1PSc!~RZ6lF6zSBm;XHEN%(QHTNAr-EshNvtDx>u)#sQz9@vebSXl*?Tk z+_XCF!X{N8tt{D`;f{C{G*0x05UCUIZg(@|4OhEiH;$%JFv0hIeh>HQ%*4D1XIqQm1iv!f*}SEx5Ck$Q(^NFLdL|H=g%!7-TJ2#n!$GHhS<#AlO$zV=c5n_@+aTaI&f2CjcA&p$@7Uhf4_3UL zS@Cq3;O1sLoqS`p@Fh13L z4#uZoeA-XrQ;|Bkx%J891I6PuL~uh0@)l_X=__vR(z{BIy@gmH?lRGAWycGkI zAEtu^sSluFK?)Y6U_sh13(~_W?wb1gY3@=C8Wwe{MW#B(`*`(sm!^W6w&O8S(9d_E zpDRZi%rY1)S5i(MucE8ED5qs#4K2O-x}~VMU~%f|YuM1$n@zW(u0J~cxrxC-VXo#a zwFkDU)Ki;q*T{wr3UyGZgF?M$3U!kd46nS=K#`Sb7f;891!aQ|IJ!aE1}XP_>fZtp z#GpNM$%2^!1ZkS16(^29VsTLNL05BD<4f3I+2#nd2lGxYwQL$6>ImXOJnGn57%IJ{*JHG_%xSRcvS&`xusPKH=QXEpW2R+F!%dn! zb21E`JDFLxk<&7>4#7=58yY;-Gs5iYHSI2rX_@qBL#PK(ys@x1=@nIo1#1_4q9v|pQZxZe$iWPuc2T<4u$^$bO53?aKJ`ot!NvNz zYw&SmaIkgn%+_tUa4U0SW$xq|gBe=foq(UvY)R>j{PkA-T_93fvCb%&<3+V`#H!$^ z#st*(C2-YXlUt+r>RV~B76_>3&rpION57P>1qSr2)ssq7_2K&XPc z3#BP4=}Qik>Ry zo9DtZI?H)R5a$DjtQyqDy=wkEC=oYWqBu`bY$yi9pr}aa-=CJfJpK9aPu2UUKi82` zeBlF|QB&OsOo}4kdg?v5XlZK$=0(|pYFJg1>1G{7vDyMxjl@3<5+Jm<;1F;``U~^BN^S7v0o;AH>;$fZ-)z{O7a( znu@{x`q!sgkbtuUJ$?T3v=&hrM2)?>y)%d!LDUGM#yzgpgNL^GC5hNvvu=;xbp}a1 zv(zBzvJ$GxBQI%eG4CT{yQ^aY*lj!CS^WChF|yUJI)l*-BJs7Lbmt7Ok>y5=8UoM7 zMvmlV2UjRfV5E%P>JFA)D+%S-=~G`gFj+XVrF$CY=^0&#^CgJoCCZl6Vrq4vkxm$TW805^@g4RpjbMT^%SLn!T$HM@yqY1NP0)N!S=-J$ zkuXHrBoQO}f_W`zrPq>cINvZzGSnpGpy#B;nBQEZ1Vx$c@)xHcztc70_FW+ovAfjs zW)Prtf+3{?o*L&7SPrBtB;a`#=M14Q=uLTf?HkGl-i>vQGR+HNrn^z})w~H;WxFv- zGmt`-DIVv--!mIORBko@Hm5YIT}t^aq$gVxzhKhp2;PBnWo#j4qDS zfgnANb3w)FJUb;BKAlTfVPDlZjW)>u0H^Z|K$2kqb?dt3Jr$(PNg`C1WRlR^0v@jK zv#l%*I;mHBy~U7^k7Q}kN1}1}7^DUU#Yua#82rDKppjVoA_Lm)bu)?~A0sNIu|=t8 zS18Jv_~^gsY#UT++n}zoP&CfuE&uFXcj3pW#us|GXGv-q=^SS8LePKaCHapc@NTTm z1?895OpckuCHyQ=>&M@W*5fY>bY-9>NFUe_c!g;030h88FujEAMo7_TONfc{w#Iu| zAipHo!SUwaB_aImD(aH+ZC?f%C4zW6qDi~Mwqcf`Rhl{WYTv-(A?R~9U`$ zNqh8EAaN^T6`g(P$%-1#S#K88fE=c-45p6$#laroIjEZ1=s{1zbF^SEwin^?TisqFaw+WmS-y7sPxC8G5bb zLi}4^d)`3zc<-$HMm<&T3yTl0UZ0*{zMih)Z?^gz9UUEg_wuFu_vq-T`R~#3@zFQO zFTa2F{kKO)FTXqb=IHp_ Date: Sun, 2 Mar 2025 13:05:57 -0300 Subject: [PATCH 7/9] fp: longhorn-crd-105.1.0+up1.7.2 --- .../longhorn-crd-105.1.0+up1.7.2.tgz | Bin 0 -> 13408 bytes .../longhorn-crd/105.1.0+up1.7.2/Chart.yaml | 11 + charts/longhorn-crd/105.1.0+up1.7.2/README.md | 2 + .../105.1.0+up1.7.2/templates/_helpers.tpl | 66 + .../105.1.0+up1.7.2/templates/crds.yaml | 4400 +++++++++++++++++ index.yaml | 15 + release.yaml | 1 + 7 files changed, 4495 insertions(+) create mode 100644 assets/longhorn-crd/longhorn-crd-105.1.0+up1.7.2.tgz create mode 100644 charts/longhorn-crd/105.1.0+up1.7.2/Chart.yaml create mode 100644 charts/longhorn-crd/105.1.0+up1.7.2/README.md create mode 100644 charts/longhorn-crd/105.1.0+up1.7.2/templates/_helpers.tpl create mode 100644 charts/longhorn-crd/105.1.0+up1.7.2/templates/crds.yaml diff --git a/assets/longhorn-crd/longhorn-crd-105.1.0+up1.7.2.tgz b/assets/longhorn-crd/longhorn-crd-105.1.0+up1.7.2.tgz new file mode 100644 index 0000000000000000000000000000000000000000..c2e4209571438fbde7aac4d6b7b72ddf793501a0 GIT binary patch literal 13408 zcmV-mG@r{KiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMYObKEwTD4fs!6)5d9Wqa1$k`gC=R#j8G8p*z+UCVJvwo`Ry zQwf?xcOzm09Dr-Zhd(8~HbLkWT$O++)JMa1GKFvXt`7E|HoKF^ zIDdC7zQtq#c#5LuU3d}D)p7Ix$ze|ZG8{=o%amb~&B4K+_~cLg08FnG@l-8Uw_f

eDWXP9~~VSosI{Z zqllsG05pdD{eKT&o-O(R9-M&R|M%ce#UJ8F@u&Lfk3ar6C=s4AyoMRNLJQ0@b~k1E zkB=+?&nm>9NW}NG;fVEq^d5448-ss>*$*!fiJq5#0b|B$*H6IVpP!V-PT&kB94rt) zOptN8C3yx(3|S2RhLROfpNMT~p2+$#t8Wy7VVX{F%5zY#@e}a-@1Woot)o5_z%5a- zn)2nLBoFd?b2I<($E5m2GjH%uz)+gN2!VrtKL7{6$i-^|pmt$Ancb;wi@ko0*cwO3 z-UtgBfJCU?M8jhFzGU|mn5U(f0lIgdlxcp^XZV+5RjUn)=j9eyBy zTUgHc;lZd5P{J#UanL?M4T@ULsF=bpIZLe5=sF^u;16kNfDK9l<3#ebxj3y^9sc=A zF*9*Kip>kOzzIq@)pkhqN57OGS@BW6Z4v7JFKVk)+o|&V&QuH_u+)rJD1$M~pwJ&1>LdUWB^jehg4kq%h$OPJ949eiH7dJ4njU{YJ$eE(gA#Oi z0@~t4!J4MvpMYQzBa(ra;>3%w%Dt@RloN0uG*QK{goJ^~0|Hhb1SHEDj`d4S7I^}htBWT9@Q4a!wxl5O696>gWseg8<5(^wOx_D3jo2AY@)aq^ zt7+38gv_5aCQ#2a!T+@)kkT0BTnWV~qiZZ#rFf%30}?jbr+9?20p^UZ0Ix6yz;B$A z_b^+YfT`#{=Tkk}wHQo)q}J5@MQQ9jW0)*lU<@Cxw^uF_hcr;GaJ;$orI>-F&rW$;*?fM|(U@I-%3Q$$YRUwr!Ry7n`u zW5j+c0p{R#i5LQJ3z>jtlp*fez@WCF=4#JHd`c@hhHy+$kp3`KN7 z@Rzc0u5?`lq=1kCNhb(Qz*-12F90NQqvsX80}P2VK~9YR)=C0ue0@n70+`I{2@q-_ zKRG;H;H=<65nZivg0s6r$x!et&nV-EFhcLwxIT0c`(R3C6 z8$%{ZEuPk1Rga|a9?K(0z1TcZccrFSt%CSTpziAR^#@QuqE<>RO7&?AFU9%@Y+^D; zOtq7AQ}l^QoKj3OWs6C$B+L11g)^}Y{*fb|iKT0HdnP%xIQ4ld4p-d#;DUfNxI)R9 zkUsBst;DMEiCBa|t7Xa`&5sp&jTZ%rub$77O7ok@RbXp0$;l0&w`8JhJ|`e!xq0vv zXWF=<7Lc+{YHy03Sc);&}jAQ6ZohmH{F%Sg3Wb6eqN3n%{ zI9NrV zK|U}@_#82YVprQ4r3r$h@mBFQukljI;0k4kwGahrlAH^jJ>5Guj(93Tq}?kbwk4W? znBJ0v!X|MPukzIK0)0*?%O>KCPu4;hZEh~{5krzWS>8kmCGFokCN0EIk411DEsK~x zs*&LK z3mMI1J}f5$lg0a8A4!rY37jRUrCFM7?I#w0u^?|w*$QTIRzJM-nz7a}FWzr@Ts)N7 z>X&X^b~2ef`6@jW`u(=t6PKzx1%uT$p}**KOcX$=m9u&!R_dMADX}VnxG#^y%9!>} zwSGmYjUlC_LMov-ci8|;%}Wh?Vf^Byi5H^^>H8iOZeuuxcuEP!vjhnmv|T0J4nYdD zWfP2?S0u_dxcGl-aO1~)b6Q+hQy-w-Hx7avGN|_To`Y&1RQo+p?Sr=>F#Evl_l4PS z$DALSePH&*6PW#1#O(Vh!WNDAZKBa-V4NASJb=;q{#*ePIbJQi?f=^_Js107fZcgl zTLPx|5)&%}0X-H-7vt$`XYRr`I6;@tVu>EQ7u_>cj}{-#oThaXUdNUOUFPqB?WK4z zwz1nLZgybDwt6@sF=BeZoyKv0Zyn%>&M;YAp*doRL_PEB1j}j^S5LQTeDDZ%zsSIu z+TBqD8?Q0Ta+qB2c#a(ecN2fbefgEf_=tk<;}QBk>`o6Q{Z~waXAEX&ad!fKLbD~M zH}cn8^>=|zC3K!qGRKQ*iMdJ?G}pXY0-zjha%=QneXHvjm>Fr7%&=)OclD%F!8}|a zAL>pIt8vWFD9cX3e|&#*T+E{U>I$tfy8UFhN`O>fO>MLK|M4haky`>)a4dZ zudH67-MEA5l8l(|w(K&G+AT2DL=X%D!5|O}0{dqW2-bgBu7ZWUE3^Nmc?d-)^xPF{ zE|$~5T<#&tA7BCyjF!^8;Y7lwA^%zfQ6p+pC_tWxvpy4)mM!FYhol1Txf38mrK!R7 zsrCE58S4WJ4lFpZ;QL&wM`Dv7WQ;F~LIXvvY@D4$(Z9iogm$O)QnbcVCRJ9sscd2N zCb0HkdeCQ<>TwcWqXb16W$m$XhE`*J5|A-?XBll*o{-v>I~PYkl1C8ygk&)?LT{B% zTspdq)fF@ta*h`^yvBGg&90f;%@~xa%^GJ7Meuc@qd^JPt$N3petuyYj zMG_jL`&&3wC(O@kD4Ue#3ct3JnD0Ei{Hx3O*oGHvsQYXX5!XZC3oVx;?Ub4)kShzm z%!|T>r2SxCuq`;UHt^@{$WtQL^DX4r6`G%B8!hLKQcp&?Shk$5;+fdh<2|d-C zSDxb+;C6|lC9vqZ>GF=_2qu;V5M4~cPdW?z3t|-HB*O`i1{UxPO&3$qae@GB&<)Hr zO~qvKd~1jcUaK8>t@5!JZ_k`pKW9UYdJ35a;SE;4rfwLle8I}MhgQBiJ=mVDuT3(# zlrb&H+=H1((QH{xoX)Kvdzpj;{E%x}t;6~LmNJp|4p5TaSuG}-r7R3_i91HZv>JP3quI%$aP>)Y3RcTa8!tI!UHnIbb)oC05t=w{D7tAm=?` zhw$hHhuh55&au;gVL4YV?rpoMA?$|or|;TdqKvR)U}zdqans@X5-fUIr;rApoi`?eQZ;PNT#P%SowDSdcJ!C+aPJZ+o$Ju(&!|3FcDXr3_#q zq%HZsv6J0_0n?ssdvOjZ(e^(nNtcGFW;Sd_Ewd2n4T*4q3YPA*Zf+CzFlJG-cMa;O z2GnmRwVP4g=Wt9(BCBn_UwU#PqX-XDUE2hwGf0Hub8zqi99)q18hPS>f*&O)L$UbJ zYq7hS?Cc%{REIq6Hpb>@FuDe#YcRU*q0u#DHw0E2SnXr-fd*C^SZ!dn_p(+G?%(wDY5IFx z^7N9%8(DSo6s%~B$^-AR4_3yUd7dN(fHH7^NyN}f5QpTT)xZ_@ESg(>Hu|!>J!tp; z2>k>l3m)UlHDrtd=B%1T<7F<}o!9t&y~3M$OufU>$DB<*CIG;0TU(qwDsD<9rixJkaM^vyu1>&@@r_j8?Oej2d?La@wZ;+I{oTHjkj6a~1%V z4{3(N4O}DD@M$yd+d>!S&p6609s}Y;(3^ZV|{0ibtT1x>VFSX z{Vz{HNc5}4YQ!d}SB?k;y=-b(Y;g+uNHhW!vSPR$<(HLefgsKrHO=}=Gh=quSGr78 z`F{@!zaBASNbG(L6J0C7F@E*kwfUI>;H-Q(8jh4EiLzO*%U+r=h;J_HpH#jEwfuu! zDiP;C~1ikPNv|lc#RPZ)*lNQs$U})yt_KP2;dSovP1*to3g6();;=2?V_n8u$yKJ)EN_ zmRXCyTBh~kE=2|8qS0WucV0--R?>I#SR^9?WFKOY9z(o~<|~ildE<4lwr0C#Uv*uUSveFPQa$SudFN_Rp*rd~$(x2G+S{ zk62)xfprdAp1?Zym~}c2{x&>fmMewahUuNUTofex<8sk!upO6+*D{zzch82EqHPz= zEDFkzNJ#uR7uT5!-IDIN7eX9Q^Z=>D*l{0O$fnz2Hr;E9 zecSzQ#+#Pc%v>|ICKjg|YF^l8w0a^0Z)H@}VF7QnNwF{uZrP=FZ7Kz!E-+SQ4m4TOcPtN{E<^J(Ay3y}xT^oyuFzn!_6aH?1qm;7 z%Vy_Il>fEytAZddewdgY736MOs3by0Hy9oSo6t3R|4J9qVH1#jb|-q+3F-(EJ*c$dCIG8l!WRCiHHFNOlR+O`WuM z=yu{J?U+`f@%pWqqcCh&3D54W5nPD(=|bEjeN0KNYNUn-%;Eg%@O!B@4Y$|5d%Wbe z=s9Cj`D>fVoYorM=6YirnT%Q}!&M4_o`cfm*))`i1{deGG2hYHXGlzV21!)iRXuFV zMYBuQsuh5LQGf3NP_Y2o9OSbA7rti0N9qdeHI)S;S)=D*Bnw8eJus4e_5LqG;069l zLe@jx1&^-peds(Xo_knp{x>+NH>ggzO z7iD=b6R`f)YgoBz*WT8y7;`vF&>KcchMJTB^sE)Ce1koU^wd}-U|A-~ zY=50T^#OhEgxQ5>nPL{BwdED&5yzI_$$B-n{Ootds>9{ml}bbxWwxlV(O5`io|aYf zF0?Hej2-@o4udc&CacoWu8@>BJZGW1khjT6w&U4;jfI3Ejm(IhtApW*eGZc~T%eI_ zS6u3K2|tf9byuzJ7f=-mVVGn;y!1g$PF66zgzV;;!1QbhF}Xr3x<>J9G6F|=x?nIy z@zuj`yRJLIx?BVuw|tF6@@C-~{ulIm@$s2)3-I_w>WgzwqgcyD_aLu$9QW!DZ0)`P z)9k>0_SDmNspLRFx^GP!+KF8h7}R=mH?p;Dl+a?U?rs-twg-f&akZUQ#QZFw1d~N~ z4=(2_*vgLlm)%Ms(5eTZ5NH(wtwNyHo&{PNW@NvBSJm*oBw+bKs|E2`VC+3a$3FT`cM{L72_oK%Cgin)LLbHF>Sq z``SR>pe$PY>X&1J%Vd_mm$seeZ1Kp2S5tWP2@_=IBbRX zR*)FJq%nGo>{5eQR|IwkXum{wXwir2YX5-~lE@GmU0LwB?mDvXZd}rOE-G zQQIz(pDS;kER9E$v$4@XtzP5o`4oIuVlJI{LckFE5axi>6%vs0GKmVz?tmJ*ih{KX z>Cez~F*T|UnPr=DjyS-X03k*hVk=AvU5qglW!haTv;mEu>2-=CSs3?k2qxL`?lgPu za#cAtiDa>l-#k}JsRCY17A~1!V0RnRSDYZSiB&{URXvgMMAa0L9?)?42r0Anq`dx& zqWoXRky7-$!($pPaS}7+v|9`v$DB*o4(?rJvm?hY0adlq(TBiQ22?#`X5BH^wkEw1 z0ZO5urlXrP<-!|JyX+MM2acX|#0D+78-iUCp5l!9tIRxu%%4`Npw^4`UPEouC2K{7 zM>KB8U$W#c6;>ksZj(eNTP$mp(bRa`N^NQaqE^b1OQCr1G;O8n%?>pIaaj(!J=W2FHi$2miS279f}dmJ=d0p6x|yKf2VT#zuDs zDYrw)L%4Fi=Mb(O!j<&DG=Q#{dI8IAEwl0}R0h=nSlDcGRM^{7-?ei%o8xu4Ws3o?GiVD>+trYT^yQ?V)`2aaP~U+&-Oym@5@nDrQ1<@5 z7pfZeo|mgD7#eJazU|1(wp1cdG&Ae7KJT!wxBmtmK&6;;Hn_^A~pE0;&1-x3?ECQ*gP64mSd#=~By zN*D;-E|E-A%Zi8;8O{LXqMm>y4yP3V{{HkzeEIa}zdu#)p8ovA+$dK@KYbA~R)BJj zSW#9mK13=Uy-Wt=(GtaZg2_U#sfxJhnOG)}qG$?}gx+44O=|$3THm$h(mvSB;FSoH z0!&oE%>gA{K(?{0AriB9;@bGejqyhphx<g?=MeA{0)F-&;ODE4 zyxk73{m*CrB|}dC@)yl@pZ`3q72OIvcZ)pNz_!VK?Kpo(-a9_@Ht^oSdj~8};Jtgy zds_$IvqZl^F4fZ!Usao^(FJ8esYlrWa zFD;?HCd?fsQvvda4!dhNz;m1+e#bMka(*H!;g5w5t#On|lZ~^=x!F@^Q7OS($HJk- zz$>H$L`OeEoCy7<@C+`Tt}tiC*?|)&KC#t=1bqhbj+X-#s%wcFg$~c&f7BiM8KUhD z(yj=4E2^DH?nJK(v18-nB|Y}8w(dic^NhZh>*h<3Lrvs9fI>~=P!l=SMBcBO$U+p_ zb!of);Ful`KO_QYAT3qTb||WP21PaaP}fcnduVKDm%yOF11PQ6^m?eSWln=>Z_k`0 zWgbeuyynzRjV)6ePLq4)WKis#%&ePATV~cltJSk1#a7P-fyCj_UY||I{5g}7AZ8agG%?`2#!HD?g#c&*!7DGzg!*p z1)mNJ4IC2Uww+Rr+8A-VhFJBsQ)`4C?Gk>*E4L|Vt7Bak%ec$Yb`&_A1n&aS*JU9T8G57bs|-_C1LEOBPj zgtaz*pyQ1WykJcsgDaFFwt-!;Q=V%rQ#GP>hQkHIvA!?8kG;KLn{Vad+Uf%+xVD08 zE4a4y%eCd76&N)09cbnZML83w{*BHy(a*1ne*T-z8d|#fs->&f#&>G$?6-!>ZZ_M# z;(m=XuI7!&qEyo)hQLotL;y$flCy&t&0(Ho2kK*Ri<1P*s#5^tSTIRyUY919O6a`= z5UOun`;E@@@8~m@nxOvLp|s1<>Ji=l$NZ_!QgE#_(;1SSk%S*T}H|E@H(YFQ;pcr(Vn35n>b2FY3V!ys!(zM3H>5K!KG zbEq&O7ySmIwB%)-3&I4mu7h%A{?xYo+VDb&uD>Z~pHaYa0%msr!Dy+l_M1Lj7E~0C zqq{mrTEE+1*r%qGU_{9z@m-_1S`o2E7rj%t~RDVzAltpNwF5s)Zh!O-zo*uj?XIj0BQG(RxT2?Cms`n>F zs45U)k}Gjm&|?n^llu1N}kjk zY2d0^ZP)h9ydIQ_MvvH2>U0ga-KV{%1K>JOQ_3=P4&Y#(C&@$$zLKAh$ePz|V7!saAYZwwz{(f$43++LU;YUjUxf87r6i>*fi7nQKK7zS*+sTcDb zzcEFN#+c{W%l_5AVs#jzEeSp~FdFy&c|cUGyS!}CbKNgQn>rlEFP70CU2)8-YSmrV zAN4`7`vkjBu>0(v-RGb16s`L9z&v#XYXogL;(Y zVfIWKvt1A0QED#A@Y5^ zH!O}hhd8m-MG{Ax1w<|ce#HtD^eq? zEjmLHT_JUU!{IH%8LD9zz`0nFLdqA*saJMd4PpVnafD=AAJ3x*aX!zJYM0cHR1^Hp zGi4cFowA-YRU5>$f6dQ?l-Js$)?Kv2U2E)7%h21{wb)yL5UcuT1KR)AXfH+eCZfgi+T=P;UATD0`j3o3vK;8gBKM#R97BR*|U z=_@!aiHX9od%s1k#d6+xQtI+Fl)b%Zb#58IenQ&dZ0$f;#;(aU^^v7uqqY!ME4spQ zoRlLK#M$pWSodFfLh2iME61V9JS+hGYl%DwU5r#7T%}n$2GiT%3T5oh5%JO$r^3)0 z^CDOVv2%S_lpokyxE(p^A_VFZejYIaqxCiZV&U1{cYI+%Dr8BwJsoO$3=q4d=?&x{lenJ;-P!=tHdH1Mm`YH33WRw*3TE;JX3sD(l zBO1x5kc;=B)X>954C~CNO(KS`RTpZkGGbW&+KL!122?9yi5S*z%7|fJc7Oj7!^&A* z=-S3SYjGX&EB&*=>L=rueTWg&i{*~w&~p!w93he;L~=a(NDjF&wl5pq3e;g{^6m*R ziP*y{6N(-`Wz;BaGq;v_H`PK>P1?t#%s4*Jn)q z(6X>ts~>a(=_wjFAi=avOkLg#o0iz-PC(saU8Av`$gnWNL7ZiJ&%86JrZ&}d2^rEa zHquW;KW1#dp`;qG+M234zFS>gHT6}a*>1Gbny*6+2UfMzg|@81x13~B8&#%#+!AS} zb3&jkSv45Cb50(gmTc^n4sof5njkaem5uM{}C}{Jz?jUTehRqFQ$HpME zI2%1UefQ?tJVsE3%R-r@p<-`kgk)?KR0DKwL25^&X-Bxg@Ooi8xRtNY!wTBu13tG0 zqF1QU4$cm>L>5Xj&SvK9N#RW1wxx(3l% z`$ZpI7iBsdt`{6tBnQSa8?8v8l!XhWjC|OrUvy!iKCsUf#t_&?q5WRYb+y0UdD5`Cj8MO~9MK57EG2l;tof zfi)5C*87@6caQn_R4!vji3zKZ%aGcVP6%Bn=vc)QbgZCb?VXOLk8;0$RT^BbZ3US- zGDl=Z#hOa6;=BHMc=u3y-cgkpfGi7h`ZvDV^TV^fijdWEdPT% zcQVc#bAVT?Jd=qc^)!52%PY;whwBh7_qIiY8?68rTYZS~J9@V-QFOy?m1erK36?mC z8M36l`0Z8uIoM?5nNo;fo&#glQhKN}dwGY)bvy=EklpBf!+S_pfDE}4FCBTOg*5I5 zo*^WU%V=~YPi(oroFgW6BtP^Alf*7e66&&zSx({vZDf~F9sN~y)HF_*@7flM8VF7^ z#jNVtFjSar?;{pP-%Vlwvl|~F<~&E>Ur5oPrs{Xm0*kOcER2 zv}&AIpVx*yZ~eX(IR=~e&- zlIdRDiKpNh1AIwM_ESBBq;Bi*t^zEr!Bd9jh%s4MuyVE;ZaD3x^C%qSQbpVB%-unzVJQ$|9`k|W%dzr!*T`0a1tUsw zo^^!si%zd)n+AMu+b>!`Zpi{=Z2ArZRBfuk{#5Td*q?&^Y47Y$#<}0j{M2Nq#p71$ zmH%Bec~27@SuPG3c00ME?nN+yCQqsC($b>1r5w*Egk}@H5f5H~167b+T`C^yGP&*B z#K)SRMjLa?HQLmc*cF-RUi)xs1u)B-1$ zp=NmVx=CO}R#J{75xn_HhuK2SVvLj*U3Aa9XIkiO!^F1@Sd*jtDN;w}@-X7-~3&08@b z`C&R(koo`$7NlT73KpdOvLHR2;;yN$pXM&bpkYzBT4btoypLCJcWEl9X*(VR1^s*n z`nhtX!7PK(awX;D@hZBii*j1_)zH$LuUm?G3l^uYzJ?85z1egt>iVP8pPLvg6y|E) zQhQ*lNeIw;h8rcgIY!SKo(4HQ|4cJXvvSWq_jfTJ6fZIE)`r~WMv zK@8e6mn@j+keE*a7aNU42#|a=lV$3Roew3_@f=6Sn1v`;!>3!Seoxa}5FUBEV&x2* z%6eB5N|HNQ+wKT*^>hU-s|Q;W+$~5F;#e+~qf%PMCLfuCkGkwvjOTO21coYGv!(Om zE2EF4J(Q7Y(Qlt}GP@z+ z3Iy9W-4-S9vJP5sbcG_yVgSjVDg>h|D6%^#rcf}?lQ~Y3fqUI)ejEn7dIp&yEmIk7 zkW|kA`T)F)lbs;;m?%5D1cm`~fT7ZBdOb!<%bW(AE_>!A4Vy#Fe_nIyHfCC;G~A@w zGbh8~xs#c78#ygA>k!=3v!TILJtNGXUeoU4n3hS8HiUWr)yw63O`~Q%HUp`8f}q|& z)z>JfbC_X1x87xEnO;$aSg>}%CtBiqCPfplgdEHeY8Rzz4ciH~tF)a<SR_0EgF_@vn-3j;!&6bqj$X{>O-vuI-73++WIbKv7N305t zYD_?lUjkPRHn}x=ufCNAYk`1j{tP7ua`a32T3|rWT0N;WRUfX84|S)9)i~y7lw~L2 zKfXUYE@n}Fb%oX#-F`BRwLlGbfWryUVft5Z8kYYDxyim3MA1_P zee+ycMrS$C2;zL;kX3`)xL3`e2PNW0OBCk`iVekJ7!(!h{QJ|gm#07f{i%BY^yfNK ziZ6U%Gis_kfk{#1TTi{`7AOBX4Q}8$KfxjtS*C@0}m_dNZ0+V4pMtuKTeqN)*=c1e1?}Ip75HP$1jQ@Q0 zUsEyIU;gq`3leaapr_A&p4K8NgQ&50w|53nBZwM7)VRmBdhpN|za$ZxYu4@2yUrkq zXO4jG!jbM z7VQa0zO>En6R`M#Qy=Imd<+L@eQf*jTi;>d(g-Fvvus4yz(uJV%c~jU*#yn!l(p^5 z6A43njQPzqN>G&9E`M?Q@jG1;Zr>Fm5xYx0 zZw3KcCm2#X;HhyQf#pETLIR#=an2C>g5H#u*S?`_;N4i)DAT+UX1W_iU(K6vRkjZl~!Q|m*;4Wan2PJU>woq-n&%A36W&W&n^ zDS79J=<68M6$IGR{+(jQ$lSkl1Lh{~_vN83}@2Jfn-F zbRbAi<6Ka2I?ql?hEM0xRoGYcO`}aR0Kn-y1CV4GK;62oc~1o?bCL*^C7C4jwt$E0 z`)n&qgHGy|UT-nv<0Dxb^pR-XJqD?PL2=R^Ee8KDC1@lTzsP{Ld)3vI z*%gX%CO-OaI@<=7+BT?bEEJ71dCNaL*IoE=s_}*1?OBpqMmmQXyb$!Cc}f1G2)rAs zb3ys#HIrlJa0x$4)cWx^qxJX;16>)Y3DO7l170DTdxDme6-+N7yAe|K*%D&nyshzG z7RWCNc5uA8cS#68yNbHxeA|~nMu{Naj%d>Eux*%SXq9G;z1lahcnJEOoeIj0;#1X` zttuYqkBs9^^=wFEseylTWJV0>z@DPr+p;5iEtLA`11OaG2&FzksgM0C^`Skc{zh)y z@UqXmQNvBvPF1w|dbQ2O^!56{G{Vw?KBthVkWg1#beHH{*v!TW-k6Va&{RPt{2G$4nmD}$+{e{rx!cn+#&HhR$0@Ek1|jO|6ZJDNI6 zRduvU5s5Kb4B}XoFUzY$6hkYagI%d$2=7^G)6)gPGP}u>pXk=(SXmY1<^?fdLWW-J zxDfxA*Pb`fJ>EO(zEMw=`@-VGtJkOJm#?R*_?xXhM@L6TKfHV?|2;Z7YW{n4e0=oH z@yl1=9)Evy^zExx-y9u(cYOTv8*sE;FzipxGswO<+IXzy67C#T>Fl4yw- zh?bCLO8&)!XD~^Ws&IC7&Oy$Vr@YKBdh*co2v2yz6Q1z+J^wEN0RR8W`|i5{egXgy C7r_1i literal 0 HcmV?d00001 diff --git a/charts/longhorn-crd/105.1.0+up1.7.2/Chart.yaml b/charts/longhorn-crd/105.1.0+up1.7.2/Chart.yaml new file mode 100644 index 0000000000..9d382842ea --- /dev/null +++ b/charts/longhorn-crd/105.1.0+up1.7.2/Chart.yaml @@ -0,0 +1,11 @@ +annotations: + catalog.cattle.io/certified: rancher + catalog.cattle.io/hidden: "true" + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/release-name: longhorn-crd +apiVersion: v1 +appVersion: v1.7.2 +description: Installs the CRDs for longhorn. +name: longhorn-crd +type: application +version: 105.1.0+up1.7.2 diff --git a/charts/longhorn-crd/105.1.0+up1.7.2/README.md b/charts/longhorn-crd/105.1.0+up1.7.2/README.md new file mode 100644 index 0000000000..d9f7f14b33 --- /dev/null +++ b/charts/longhorn-crd/105.1.0+up1.7.2/README.md @@ -0,0 +1,2 @@ +# longhorn-crd +A Rancher chart that installs the CRDs used by longhorn. diff --git a/charts/longhorn-crd/105.1.0+up1.7.2/templates/_helpers.tpl b/charts/longhorn-crd/105.1.0+up1.7.2/templates/_helpers.tpl new file mode 100644 index 0000000000..3fbc2ac02f --- /dev/null +++ b/charts/longhorn-crd/105.1.0+up1.7.2/templates/_helpers.tpl @@ -0,0 +1,66 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "longhorn.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +*/}} +{{- define "longhorn.fullname" -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "longhorn.managerIP" -}} +{{- $fullname := (include "longhorn.fullname" .) -}} +{{- printf "http://%s-backend:9500" $fullname | trunc 63 | trimSuffix "-" -}} +{{- end -}} + + +{{- define "secret" }} +{{- printf "{\"auths\": {\"%s\": {\"auth\": \"%s\"}}}" .Values.privateRegistry.registryUrl (printf "%s:%s" .Values.privateRegistry.registryUser .Values.privateRegistry.registryPasswd | b64enc) | b64enc }} +{{- end }} + +{{- /* +longhorn.labels generates the standard Helm labels. +*/ -}} +{{- define "longhorn.labels" -}} +app.kubernetes.io/name: {{ template "longhorn.name" . }} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +app.kubernetes.io/instance: {{ .Release.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +{{- end -}} + + +{{- define "system_default_registry" -}} +{{- if .Values.global.cattle.systemDefaultRegistry -}} +{{- printf "%s/" .Values.global.cattle.systemDefaultRegistry -}} +{{- else -}} +{{- "" -}} +{{- end -}} +{{- end -}} + +{{- define "registry_url" -}} +{{- if .Values.privateRegistry.registryUrl -}} +{{- printf "%s/" .Values.privateRegistry.registryUrl -}} +{{- else -}} +{{ include "system_default_registry" . }} +{{- end -}} +{{- end -}} + +{{- /* + define the longhorn release namespace +*/ -}} +{{- define "release_namespace" -}} +{{- if .Values.namespaceOverride -}} +{{- .Values.namespaceOverride -}} +{{- else -}} +{{- .Release.Namespace -}} +{{- end -}} +{{- end -}} diff --git a/charts/longhorn-crd/105.1.0+up1.7.2/templates/crds.yaml b/charts/longhorn-crd/105.1.0+up1.7.2/templates/crds.yaml new file mode 100644 index 0000000000..3b78dd7ad3 --- /dev/null +++ b/charts/longhorn-crd/105.1.0+up1.7.2/templates/crds.yaml @@ -0,0 +1,4400 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: backingimagedatasources.longhorn.io +spec: + group: longhorn.io + names: + kind: BackingImageDataSource + listKind: BackingImageDataSourceList + plural: backingimagedatasources + shortNames: + - lhbids + singular: backingimagedatasource + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The current state of the pod used to provision the backing image + file from source + jsonPath: .status.currentState + name: State + type: string + - description: The data source type + jsonPath: .spec.sourceType + name: SourceType + type: string + - description: The node the backing image file will be prepared on + jsonPath: .spec.nodeID + name: Node + type: string + - description: The disk the backing image file will be prepared on + jsonPath: .spec.diskUUID + name: DiskUUID + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: BackingImageDataSource is where Longhorn stores backing image + data source object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The system generated UUID of the provisioned backing image file + jsonPath: .spec.uuid + name: UUID + type: string + - description: The current state of the pod used to provision the backing image + file from source + jsonPath: .status.currentState + name: State + type: string + - description: The data source type + jsonPath: .spec.sourceType + name: SourceType + type: string + - description: The backing image file size + jsonPath: .status.size + name: Size + type: string + - description: The node the backing image file will be prepared on + jsonPath: .spec.nodeID + name: Node + type: string + - description: The disk the backing image file will be prepared on + jsonPath: .spec.diskUUID + name: DiskUUID + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: BackingImageDataSource is where Longhorn stores backing image + data source object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackingImageDataSourceSpec defines the desired state of the + Longhorn backing image data source + properties: + checksum: + type: string + diskPath: + type: string + diskUUID: + type: string + fileTransferred: + type: boolean + nodeID: + type: string + parameters: + additionalProperties: + type: string + type: object + sourceType: + enum: + - download + - upload + - export-from-volume + - restore + - clone + type: string + uuid: + type: string + type: object + status: + description: BackingImageDataSourceStatus defines the observed state of + the Longhorn backing image data source + properties: + checksum: + type: string + currentState: + type: string + ip: + type: string + message: + type: string + ownerID: + type: string + progress: + type: integer + runningParameters: + additionalProperties: + type: string + nullable: true + type: object + size: + format: int64 + type: integer + storageIP: + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: backingimagemanagers.longhorn.io +spec: + group: longhorn.io + names: + kind: BackingImageManager + listKind: BackingImageManagerList + plural: backingimagemanagers + shortNames: + - lhbim + singular: backingimagemanager + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The current state of the manager + jsonPath: .status.currentState + name: State + type: string + - description: The image the manager pod will use + jsonPath: .spec.image + name: Image + type: string + - description: The node the manager is on + jsonPath: .spec.nodeID + name: Node + type: string + - description: The disk the manager is responsible for + jsonPath: .spec.diskUUID + name: DiskUUID + type: string + - description: The disk path the manager is using + jsonPath: .spec.diskPath + name: DiskPath + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: BackingImageManager is where Longhorn stores backing image manager + object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The current state of the manager + jsonPath: .status.currentState + name: State + type: string + - description: The image the manager pod will use + jsonPath: .spec.image + name: Image + type: string + - description: The node the manager is on + jsonPath: .spec.nodeID + name: Node + type: string + - description: The disk the manager is responsible for + jsonPath: .spec.diskUUID + name: DiskUUID + type: string + - description: The disk path the manager is using + jsonPath: .spec.diskPath + name: DiskPath + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: BackingImageManager is where Longhorn stores backing image manager + object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackingImageManagerSpec defines the desired state of the + Longhorn backing image manager + properties: + backingImages: + additionalProperties: + type: string + type: object + diskPath: + type: string + diskUUID: + type: string + image: + type: string + nodeID: + type: string + type: object + status: + description: BackingImageManagerStatus defines the observed state of the + Longhorn backing image manager + properties: + apiMinVersion: + type: integer + apiVersion: + type: integer + backingImageFileMap: + additionalProperties: + properties: + currentChecksum: + type: string + message: + type: string + name: + type: string + progress: + type: integer + senderManagerAddress: + type: string + sendingReference: + type: integer + size: + format: int64 + type: integer + state: + type: string + uuid: + type: string + virtualSize: + format: int64 + type: integer + type: object + nullable: true + type: object + currentState: + type: string + ip: + type: string + ownerID: + type: string + storageIP: + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: backingimages.longhorn.io +spec: + conversion: + strategy: Webhook + webhook: + clientConfig: + service: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} + path: /v1/webhook/conversion + port: 9501 + conversionReviewVersions: + - v1beta2 + - v1beta1 + group: longhorn.io + names: + kind: BackingImage + listKind: BackingImageList + plural: backingimages + shortNames: + - lhbi + singular: backingimage + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The backing image name + jsonPath: .spec.image + name: Image + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: BackingImage is where Longhorn stores backing image object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The system generated UUID + jsonPath: .status.uuid + name: UUID + type: string + - description: The source of the backing image file data + jsonPath: .spec.sourceType + name: SourceType + type: string + - description: The backing image file size in each disk + jsonPath: .status.size + name: Size + type: string + - description: The virtual size of the image (may be larger than file size) + jsonPath: .status.virtualSize + name: VirtualSize + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: BackingImage is where Longhorn stores backing image object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackingImageSpec defines the desired state of the Longhorn + backing image + properties: + checksum: + type: string + diskFileSpecMap: + additionalProperties: + properties: + evictionRequested: + type: boolean + type: object + type: object + diskSelector: + items: + type: string + type: array + disks: + additionalProperties: + type: string + description: Deprecated. We are now using DiskFileSpecMap to assign + different spec to the file on different disks. + type: object + minNumberOfCopies: + type: integer + nodeSelector: + items: + type: string + type: array + secret: + type: string + secretNamespace: + type: string + sourceParameters: + additionalProperties: + type: string + type: object + sourceType: + enum: + - download + - upload + - export-from-volume + - restore + - clone + type: string + type: object + status: + description: BackingImageStatus defines the observed state of the Longhorn + backing image status + properties: + checksum: + type: string + diskFileStatusMap: + additionalProperties: + properties: + lastStateTransitionTime: + type: string + message: + type: string + progress: + type: integer + state: + type: string + type: object + nullable: true + type: object + diskLastRefAtMap: + additionalProperties: + type: string + nullable: true + type: object + ownerID: + type: string + size: + format: int64 + type: integer + uuid: + type: string + virtualSize: + description: Virtual size of image, which may be larger than physical + size. Will be zero until known (e.g. while a backing image is uploading) + format: int64 + type: integer + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: backupbackingimages.longhorn.io +spec: + group: longhorn.io + names: + kind: BackupBackingImage + listKind: BackupBackingImageList + plural: backupbackingimages + shortNames: + - lhbbi + singular: backupbackingimage + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The backing image name + jsonPath: .status.backingImage + name: BackingImage + type: string + - description: The backing image size + jsonPath: .status.size + name: Size + type: string + - description: The backing image backup upload finished time + jsonPath: .status.backupCreatedAt + name: BackupCreatedAt + type: string + - description: The backing image backup state + jsonPath: .status.state + name: State + type: string + - description: The last synced time + jsonPath: .status.lastSyncedAt + name: LastSyncedAt + type: string + name: v1beta2 + schema: + openAPIV3Schema: + description: BackupBackingImage is where Longhorn stores backing image backup + object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackupBackingImageSpec defines the desired state of the Longhorn + backing image backup + properties: + labels: + additionalProperties: + type: string + description: The labels of backing image backup. + type: object + syncRequestedAt: + description: The time to request run sync the remote backing image + backup. + format: date-time + nullable: true + type: string + userCreated: + description: |- + Is this CR created by user through API or UI. + Required + type: boolean + required: + - userCreated + type: object + status: + description: BackupBackingImageStatus defines the observed state of the + Longhorn backing image backup + properties: + backingImage: + description: The backing image name. + type: string + backupCreatedAt: + description: The backing image backup upload finished time. + type: string + checksum: + description: The checksum of the backing image. + type: string + compressionMethod: + description: Compression method + type: string + error: + description: The error message when taking the backing image backup. + type: string + labels: + additionalProperties: + type: string + description: The labels of backing image backup. + nullable: true + type: object + lastSyncedAt: + description: The last time that the backing image backup was synced + with the remote backup target. + format: date-time + nullable: true + type: string + managerAddress: + description: The address of the backing image manager that runs backing + image backup. + type: string + messages: + additionalProperties: + type: string + description: The error messages when listing or inspecting backing + image backup. + nullable: true + type: object + ownerID: + description: The node ID on which the controller is responsible to + reconcile this CR. + type: string + progress: + description: The backing image backup progress. + type: integer + size: + description: The backing image size. + format: int64 + type: integer + state: + description: |- + The backing image backup creation state. + Can be "", "InProgress", "Completed", "Error", "Unknown". + type: string + url: + description: The backing image backup URL. + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: backups.longhorn.io +spec: + group: longhorn.io + names: + kind: Backup + listKind: BackupList + plural: backups + shortNames: + - lhb + singular: backup + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The snapshot name + jsonPath: .status.snapshotName + name: SnapshotName + type: string + - description: The snapshot size + jsonPath: .status.size + name: SnapshotSize + type: string + - description: The snapshot creation time + jsonPath: .status.snapshotCreatedAt + name: SnapshotCreatedAt + type: string + - description: The backup state + jsonPath: .status.state + name: State + type: string + - description: The backup last synced time + jsonPath: .status.lastSyncedAt + name: LastSyncedAt + type: string + name: v1beta1 + schema: + openAPIV3Schema: + description: Backup is where Longhorn stores backup object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The snapshot name + jsonPath: .status.snapshotName + name: SnapshotName + type: string + - description: The snapshot size + jsonPath: .status.size + name: SnapshotSize + type: string + - description: The snapshot creation time + jsonPath: .status.snapshotCreatedAt + name: SnapshotCreatedAt + type: string + - description: The backup state + jsonPath: .status.state + name: State + type: string + - description: The backup last synced time + jsonPath: .status.lastSyncedAt + name: LastSyncedAt + type: string + name: v1beta2 + schema: + openAPIV3Schema: + description: Backup is where Longhorn stores backup object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackupSpec defines the desired state of the Longhorn backup + properties: + backupMode: + description: |- + The backup mode of this backup. + Can be "full" or "incremental" + enum: + - full + - incremental + - "" + type: string + labels: + additionalProperties: + type: string + description: The labels of snapshot backup. + type: object + snapshotName: + description: The snapshot name. + type: string + syncRequestedAt: + description: The time to request run sync the remote backup. + format: date-time + nullable: true + type: string + type: object + status: + description: BackupStatus defines the observed state of the Longhorn backup + properties: + backupCreatedAt: + description: The snapshot backup upload finished time. + type: string + compressionMethod: + description: Compression method + type: string + error: + description: The error message when taking the snapshot backup. + type: string + labels: + additionalProperties: + type: string + description: The labels of snapshot backup. + nullable: true + type: object + lastSyncedAt: + description: The last time that the backup was synced with the remote + backup target. + format: date-time + nullable: true + type: string + messages: + additionalProperties: + type: string + description: The error messages when calling longhorn engine on listing + or inspecting backups. + nullable: true + type: object + newlyUploadDataSize: + description: Size in bytes of newly uploaded data + type: string + ownerID: + description: The node ID on which the controller is responsible to + reconcile this backup CR. + type: string + progress: + description: The snapshot backup progress. + type: integer + reUploadedDataSize: + description: Size in bytes of reuploaded data + type: string + replicaAddress: + description: The address of the replica that runs snapshot backup. + type: string + size: + description: The snapshot size. + type: string + snapshotCreatedAt: + description: The snapshot creation time. + type: string + snapshotName: + description: The snapshot name. + type: string + state: + description: |- + The backup creation state. + Can be "", "InProgress", "Completed", "Error", "Unknown". + type: string + url: + description: The snapshot backup URL. + type: string + volumeBackingImageName: + description: The volume's backing image name. + type: string + volumeCreated: + description: The volume creation time. + type: string + volumeName: + description: The volume name. + type: string + volumeSize: + description: The volume size. + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: backuptargets.longhorn.io +spec: + conversion: + strategy: Webhook + webhook: + clientConfig: + service: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} + path: /v1/webhook/conversion + port: 9501 + conversionReviewVersions: + - v1beta2 + - v1beta1 + group: longhorn.io + names: + kind: BackupTarget + listKind: BackupTargetList + plural: backuptargets + shortNames: + - lhbt + singular: backuptarget + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The backup target URL + jsonPath: .spec.backupTargetURL + name: URL + type: string + - description: The backup target credential secret + jsonPath: .spec.credentialSecret + name: Credential + type: string + - description: The backup target poll interval + jsonPath: .spec.pollInterval + name: LastBackupAt + type: string + - description: Indicate whether the backup target is available or not + jsonPath: .status.available + name: Available + type: boolean + - description: The backup target last synced time + jsonPath: .status.lastSyncedAt + name: LastSyncedAt + type: string + name: v1beta1 + schema: + openAPIV3Schema: + description: BackupTarget is where Longhorn stores backup target object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The backup target URL + jsonPath: .spec.backupTargetURL + name: URL + type: string + - description: The backup target credential secret + jsonPath: .spec.credentialSecret + name: Credential + type: string + - description: The backup target poll interval + jsonPath: .spec.pollInterval + name: LastBackupAt + type: string + - description: Indicate whether the backup target is available or not + jsonPath: .status.available + name: Available + type: boolean + - description: The backup target last synced time + jsonPath: .status.lastSyncedAt + name: LastSyncedAt + type: string + name: v1beta2 + schema: + openAPIV3Schema: + description: BackupTarget is where Longhorn stores backup target object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackupTargetSpec defines the desired state of the Longhorn + backup target + properties: + backupTargetURL: + description: The backup target URL. + type: string + credentialSecret: + description: The backup target credential secret. + type: string + pollInterval: + description: The interval that the cluster needs to run sync with + the backup target. + type: string + syncRequestedAt: + description: The time to request run sync the remote backup target. + format: date-time + nullable: true + type: string + type: object + status: + description: BackupTargetStatus defines the observed state of the Longhorn + backup target + properties: + available: + description: Available indicates if the remote backup target is available + or not. + type: boolean + conditions: + description: Records the reason on why the backup target is unavailable. + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + lastSyncedAt: + description: The last time that the controller synced with the remote + backup target. + format: date-time + nullable: true + type: string + ownerID: + description: The node ID on which the controller is responsible to + reconcile this backup target CR. + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: backupvolumes.longhorn.io +spec: + group: longhorn.io + names: + kind: BackupVolume + listKind: BackupVolumeList + plural: backupvolumes + shortNames: + - lhbv + singular: backupvolume + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The backup volume creation time + jsonPath: .status.createdAt + name: CreatedAt + type: string + - description: The backup volume last backup name + jsonPath: .status.lastBackupName + name: LastBackupName + type: string + - description: The backup volume last backup time + jsonPath: .status.lastBackupAt + name: LastBackupAt + type: string + - description: The backup volume last synced time + jsonPath: .status.lastSyncedAt + name: LastSyncedAt + type: string + name: v1beta1 + schema: + openAPIV3Schema: + description: BackupVolume is where Longhorn stores backup volume object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The backup volume creation time + jsonPath: .status.createdAt + name: CreatedAt + type: string + - description: The backup volume last backup name + jsonPath: .status.lastBackupName + name: LastBackupName + type: string + - description: The backup volume last backup time + jsonPath: .status.lastBackupAt + name: LastBackupAt + type: string + - description: The backup volume last synced time + jsonPath: .status.lastSyncedAt + name: LastSyncedAt + type: string + name: v1beta2 + schema: + openAPIV3Schema: + description: BackupVolume is where Longhorn stores backup volume object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackupVolumeSpec defines the desired state of the Longhorn + backup volume + properties: + syncRequestedAt: + description: The time to request run sync the remote backup volume. + format: date-time + nullable: true + type: string + type: object + status: + description: BackupVolumeStatus defines the observed state of the Longhorn + backup volume + properties: + backingImageChecksum: + description: the backing image checksum. + type: string + backingImageName: + description: The backing image name. + type: string + createdAt: + description: The backup volume creation time. + type: string + dataStored: + description: The backup volume block count. + type: string + labels: + additionalProperties: + type: string + description: The backup volume labels. + nullable: true + type: object + lastBackupAt: + description: The latest volume backup time. + type: string + lastBackupName: + description: The latest volume backup name. + type: string + lastModificationTime: + description: The backup volume config last modification time. + format: date-time + nullable: true + type: string + lastSyncedAt: + description: The last time that the backup volume was synced into + the cluster. + format: date-time + nullable: true + type: string + messages: + additionalProperties: + type: string + description: The error messages when call longhorn engine on list + or inspect backup volumes. + nullable: true + type: object + ownerID: + description: The node ID on which the controller is responsible to + reconcile this backup volume CR. + type: string + size: + description: The backup volume size. + type: string + storageClassName: + description: the storage class name of pv/pvc binding with the volume. + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: engineimages.longhorn.io +spec: + conversion: + strategy: Webhook + webhook: + clientConfig: + service: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} + path: /v1/webhook/conversion + port: 9501 + conversionReviewVersions: + - v1beta2 + - v1beta1 + group: longhorn.io + names: + kind: EngineImage + listKind: EngineImageList + plural: engineimages + shortNames: + - lhei + singular: engineimage + preserveUnknownFields: false + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: State of the engine image + jsonPath: .status.state + name: State + type: string + - description: The Longhorn engine image + jsonPath: .spec.image + name: Image + type: string + - description: Number of resources using the engine image + jsonPath: .status.refCount + name: RefCount + type: integer + - description: The build date of the engine image + jsonPath: .status.buildDate + name: BuildDate + type: date + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: EngineImage is where Longhorn stores engine image object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: Compatibility of the engine image + jsonPath: .status.incompatible + name: Incompatible + type: boolean + - description: State of the engine image + jsonPath: .status.state + name: State + type: string + - description: The Longhorn engine image + jsonPath: .spec.image + name: Image + type: string + - description: Number of resources using the engine image + jsonPath: .status.refCount + name: RefCount + type: integer + - description: The build date of the engine image + jsonPath: .status.buildDate + name: BuildDate + type: date + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: EngineImage is where Longhorn stores engine image object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: EngineImageSpec defines the desired state of the Longhorn + engine image + properties: + image: + minLength: 1 + type: string + required: + - image + type: object + status: + description: EngineImageStatus defines the observed state of the Longhorn + engine image + properties: + buildDate: + type: string + cliAPIMinVersion: + type: integer + cliAPIVersion: + type: integer + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + controllerAPIMinVersion: + type: integer + controllerAPIVersion: + type: integer + dataFormatMinVersion: + type: integer + dataFormatVersion: + type: integer + gitCommit: + type: string + incompatible: + type: boolean + noRefSince: + type: string + nodeDeploymentMap: + additionalProperties: + type: boolean + nullable: true + type: object + ownerID: + type: string + refCount: + type: integer + state: + type: string + version: + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: engines.longhorn.io +spec: + group: longhorn.io + names: + kind: Engine + listKind: EngineList + plural: engines + shortNames: + - lhe + singular: engine + preserveUnknownFields: false + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The current state of the engine + jsonPath: .status.currentState + name: State + type: string + - description: The node that the engine is on + jsonPath: .spec.nodeID + name: Node + type: string + - description: The instance manager of the engine + jsonPath: .status.instanceManagerName + name: InstanceManager + type: string + - description: The current image of the engine + jsonPath: .status.currentImage + name: Image + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: Engine is where Longhorn stores engine object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The data engine of the engine + jsonPath: .spec.dataEngine + name: Data Engine + type: string + - description: The current state of the engine + jsonPath: .status.currentState + name: State + type: string + - description: The node that the engine is on + jsonPath: .spec.nodeID + name: Node + type: string + - description: The instance manager of the engine + jsonPath: .status.instanceManagerName + name: InstanceManager + type: string + - description: The current image of the engine + jsonPath: .status.currentImage + name: Image + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: Engine is where Longhorn stores engine object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: EngineSpec defines the desired state of the Longhorn engine + properties: + active: + type: boolean + backendStoreDriver: + description: Deprecated:Replaced by field `dataEngine`. + type: string + backupVolume: + type: string + dataEngine: + enum: + - v1 + - v2 + type: string + desireState: + type: string + disableFrontend: + type: boolean + engineImage: + description: 'Deprecated: Replaced by field `image`.' + type: string + frontend: + enum: + - blockdev + - iscsi + - nvmf + - "" + type: string + image: + type: string + logRequested: + type: boolean + nodeID: + type: string + replicaAddressMap: + additionalProperties: + type: string + type: object + requestedBackupRestore: + type: string + requestedDataSource: + type: string + revisionCounterDisabled: + type: boolean + salvageRequested: + type: boolean + snapshotMaxCount: + type: integer + snapshotMaxSize: + format: int64 + type: string + unmapMarkSnapChainRemovedEnabled: + type: boolean + upgradedReplicaAddressMap: + additionalProperties: + type: string + type: object + volumeName: + type: string + volumeSize: + format: int64 + type: string + type: object + status: + description: EngineStatus defines the observed state of the Longhorn engine + properties: + backupStatus: + additionalProperties: + properties: + backupURL: + type: string + error: + type: string + progress: + type: integer + replicaAddress: + type: string + snapshotName: + type: string + state: + type: string + type: object + nullable: true + type: object + cloneStatus: + additionalProperties: + properties: + error: + type: string + fromReplicaAddress: + type: string + isCloning: + type: boolean + progress: + type: integer + snapshotName: + type: string + state: + type: string + type: object + nullable: true + type: object + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + currentImage: + type: string + currentReplicaAddressMap: + additionalProperties: + type: string + nullable: true + type: object + currentSize: + format: int64 + type: string + currentState: + type: string + endpoint: + type: string + instanceManagerName: + type: string + ip: + type: string + isExpanding: + type: boolean + lastExpansionError: + type: string + lastExpansionFailedAt: + type: string + lastRestoredBackup: + type: string + logFetched: + type: boolean + ownerID: + type: string + port: + type: integer + purgeStatus: + additionalProperties: + properties: + error: + type: string + isPurging: + type: boolean + progress: + type: integer + state: + type: string + type: object + nullable: true + type: object + rebuildStatus: + additionalProperties: + properties: + error: + type: string + fromReplicaAddress: + type: string + isRebuilding: + type: boolean + progress: + type: integer + state: + type: string + type: object + nullable: true + type: object + replicaModeMap: + additionalProperties: + type: string + nullable: true + type: object + replicaTransitionTimeMap: + additionalProperties: + type: string + description: |- + ReplicaTransitionTimeMap records the time a replica in ReplicaModeMap transitions from one mode to another (or + from not being in the ReplicaModeMap to being in it). This information is sometimes required by other controllers + (e.g. the volume controller uses it to determine the correct value for replica.Spec.lastHealthyAt). + type: object + restoreStatus: + additionalProperties: + properties: + backupURL: + type: string + currentRestoringBackup: + type: string + error: + type: string + filename: + type: string + isRestoring: + type: boolean + lastRestored: + type: string + progress: + type: integer + state: + type: string + type: object + nullable: true + type: object + salvageExecuted: + type: boolean + snapshotMaxCount: + type: integer + snapshotMaxSize: + format: int64 + type: string + snapshots: + additionalProperties: + properties: + children: + additionalProperties: + type: boolean + nullable: true + type: object + created: + type: string + labels: + additionalProperties: + type: string + nullable: true + type: object + name: + type: string + parent: + type: string + removed: + type: boolean + size: + type: string + usercreated: + type: boolean + type: object + nullable: true + type: object + snapshotsError: + type: string + started: + type: boolean + storageIP: + type: string + unmapMarkSnapChainRemovedEnabled: + type: boolean + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: instancemanagers.longhorn.io +spec: + group: longhorn.io + names: + kind: InstanceManager + listKind: InstanceManagerList + plural: instancemanagers + shortNames: + - lhim + singular: instancemanager + preserveUnknownFields: false + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The state of the instance manager + jsonPath: .status.currentState + name: State + type: string + - description: The type of the instance manager (engine or replica) + jsonPath: .spec.type + name: Type + type: string + - description: The node that the instance manager is running on + jsonPath: .spec.nodeID + name: Node + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: InstanceManager is where Longhorn stores instance manager object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The data engine of the instance manager + jsonPath: .spec.dataEngine + name: Data Engine + type: string + - description: The state of the instance manager + jsonPath: .status.currentState + name: State + type: string + - description: The type of the instance manager (engine or replica) + jsonPath: .spec.type + name: Type + type: string + - description: The node that the instance manager is running on + jsonPath: .spec.nodeID + name: Node + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: InstanceManager is where Longhorn stores instance manager object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: InstanceManagerSpec defines the desired state of the Longhorn + instance manager + properties: + dataEngine: + type: string + image: + type: string + nodeID: + type: string + type: + enum: + - aio + - engine + - replica + type: string + type: object + status: + description: InstanceManagerStatus defines the observed state of the Longhorn + instance manager + properties: + apiMinVersion: + type: integer + apiVersion: + type: integer + currentState: + type: string + instanceEngines: + additionalProperties: + properties: + spec: + properties: + backendStoreDriver: + description: Deprecated:Replaced by field `dataEngine`. + type: string + dataEngine: + type: string + name: + type: string + type: object + status: + properties: + conditions: + additionalProperties: + type: boolean + nullable: true + type: object + endpoint: + type: string + errorMsg: + type: string + listen: + type: string + portEnd: + format: int32 + type: integer + portStart: + format: int32 + type: integer + resourceVersion: + format: int64 + type: integer + state: + type: string + targetPortEnd: + format: int32 + type: integer + targetPortStart: + format: int32 + type: integer + type: + type: string + type: object + type: object + nullable: true + type: object + instanceReplicas: + additionalProperties: + properties: + spec: + properties: + backendStoreDriver: + description: Deprecated:Replaced by field `dataEngine`. + type: string + dataEngine: + type: string + name: + type: string + type: object + status: + properties: + conditions: + additionalProperties: + type: boolean + nullable: true + type: object + endpoint: + type: string + errorMsg: + type: string + listen: + type: string + portEnd: + format: int32 + type: integer + portStart: + format: int32 + type: integer + resourceVersion: + format: int64 + type: integer + state: + type: string + targetPortEnd: + format: int32 + type: integer + targetPortStart: + format: int32 + type: integer + type: + type: string + type: object + type: object + nullable: true + type: object + instances: + additionalProperties: + properties: + spec: + properties: + backendStoreDriver: + description: Deprecated:Replaced by field `dataEngine`. + type: string + dataEngine: + type: string + name: + type: string + type: object + status: + properties: + conditions: + additionalProperties: + type: boolean + nullable: true + type: object + endpoint: + type: string + errorMsg: + type: string + listen: + type: string + portEnd: + format: int32 + type: integer + portStart: + format: int32 + type: integer + resourceVersion: + format: int64 + type: integer + state: + type: string + targetPortEnd: + format: int32 + type: integer + targetPortStart: + format: int32 + type: integer + type: + type: string + type: object + type: object + description: 'Deprecated: Replaced by InstanceEngines and InstanceReplicas' + nullable: true + type: object + ip: + type: string + ownerID: + type: string + proxyApiMinVersion: + type: integer + proxyApiVersion: + type: integer + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: nodes.longhorn.io +spec: + conversion: + strategy: Webhook + webhook: + clientConfig: + service: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} + path: /v1/webhook/conversion + port: 9501 + conversionReviewVersions: + - v1beta2 + - v1beta1 + group: longhorn.io + names: + kind: Node + listKind: NodeList + plural: nodes + shortNames: + - lhn + singular: node + preserveUnknownFields: false + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: Indicate whether the node is ready + jsonPath: .status.conditions['Ready']['status'] + name: Ready + type: string + - description: Indicate whether the user disabled/enabled replica scheduling for + the node + jsonPath: .spec.allowScheduling + name: AllowScheduling + type: boolean + - description: Indicate whether Longhorn can schedule replicas on the node + jsonPath: .status.conditions['Schedulable']['status'] + name: Schedulable + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: Node is where Longhorn stores Longhorn node object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: Indicate whether the node is ready + jsonPath: .status.conditions[?(@.type=='Ready')].status + name: Ready + type: string + - description: Indicate whether the user disabled/enabled replica scheduling for + the node + jsonPath: .spec.allowScheduling + name: AllowScheduling + type: boolean + - description: Indicate whether Longhorn can schedule replicas on the node + jsonPath: .status.conditions[?(@.type=='Schedulable')].status + name: Schedulable + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: Node is where Longhorn stores Longhorn node object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: NodeSpec defines the desired state of the Longhorn node + properties: + allowScheduling: + type: boolean + disks: + additionalProperties: + properties: + allowScheduling: + type: boolean + diskDriver: + enum: + - "" + - auto + - aio + type: string + diskType: + enum: + - filesystem + - block + type: string + evictionRequested: + type: boolean + path: + type: string + storageReserved: + format: int64 + type: integer + tags: + items: + type: string + type: array + type: object + type: object + evictionRequested: + type: boolean + instanceManagerCPURequest: + type: integer + name: + type: string + tags: + items: + type: string + type: array + type: object + status: + description: NodeStatus defines the observed state of the Longhorn node + properties: + autoEvicting: + type: boolean + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + diskStatus: + additionalProperties: + properties: + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from + one status to another. + type: string + message: + description: Human-readable message indicating details + about last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the + condition's last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + diskDriver: + type: string + diskName: + type: string + diskPath: + type: string + diskType: + type: string + diskUUID: + type: string + filesystemType: + type: string + instanceManagerName: + type: string + scheduledReplica: + additionalProperties: + format: int64 + type: integer + nullable: true + type: object + storageAvailable: + format: int64 + type: integer + storageMaximum: + format: int64 + type: integer + storageScheduled: + format: int64 + type: integer + type: object + nullable: true + type: object + region: + type: string + snapshotCheckStatus: + properties: + lastPeriodicCheckedAt: + format: date-time + type: string + type: object + zone: + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: orphans.longhorn.io +spec: + group: longhorn.io + names: + kind: Orphan + listKind: OrphanList + plural: orphans + shortNames: + - lho + singular: orphan + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The type of the orphan + jsonPath: .spec.orphanType + name: Type + type: string + - description: The node that the orphan is on + jsonPath: .spec.nodeID + name: Node + type: string + name: v1beta2 + schema: + openAPIV3Schema: + description: Orphan is where Longhorn stores orphan object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: OrphanSpec defines the desired state of the Longhorn orphaned + data + properties: + nodeID: + description: The node ID on which the controller is responsible to + reconcile this orphan CR. + type: string + orphanType: + description: |- + The type of the orphaned data. + Can be "replica". + type: string + parameters: + additionalProperties: + type: string + description: The parameters of the orphaned data + type: object + type: object + status: + description: OrphanStatus defines the observed state of the Longhorn orphaned + data + properties: + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + ownerID: + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: recurringjobs.longhorn.io +spec: + group: longhorn.io + names: + kind: RecurringJob + listKind: RecurringJobList + plural: recurringjobs + shortNames: + - lhrj + singular: recurringjob + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: Sets groupings to the jobs. When set to "default" group will be + added to the volume label when no other job label exist in volume + jsonPath: .spec.groups + name: Groups + type: string + - description: Should be one of "backup" or "snapshot" + jsonPath: .spec.task + name: Task + type: string + - description: The cron expression represents recurring job scheduling + jsonPath: .spec.cron + name: Cron + type: string + - description: The number of snapshots/backups to keep for the volume + jsonPath: .spec.retain + name: Retain + type: integer + - description: The concurrent job to run by each cron job + jsonPath: .spec.concurrency + name: Concurrency + type: integer + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + - description: Specify the labels + jsonPath: .spec.labels + name: Labels + type: string + name: v1beta1 + schema: + openAPIV3Schema: + description: RecurringJob is where Longhorn stores recurring job object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: Sets groupings to the jobs. When set to "default" group will be + added to the volume label when no other job label exist in volume + jsonPath: .spec.groups + name: Groups + type: string + - description: Should be one of "snapshot", "snapshot-force-create", "snapshot-cleanup", + "snapshot-delete", "backup", "backup-force-create" or "filesystem-trim" + jsonPath: .spec.task + name: Task + type: string + - description: The cron expression represents recurring job scheduling + jsonPath: .spec.cron + name: Cron + type: string + - description: The number of snapshots/backups to keep for the volume + jsonPath: .spec.retain + name: Retain + type: integer + - description: The concurrent job to run by each cron job + jsonPath: .spec.concurrency + name: Concurrency + type: integer + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + - description: Specify the labels + jsonPath: .spec.labels + name: Labels + type: string + name: v1beta2 + schema: + openAPIV3Schema: + description: RecurringJob is where Longhorn stores recurring job object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: RecurringJobSpec defines the desired state of the Longhorn + recurring job + properties: + concurrency: + description: The concurrency of taking the snapshot/backup. + type: integer + cron: + description: The cron setting. + type: string + groups: + description: The recurring job group. + items: + type: string + type: array + labels: + additionalProperties: + type: string + description: The label of the snapshot/backup. + type: object + name: + description: The recurring job name. + type: string + parameters: + additionalProperties: + type: string + description: |- + The parameters of the snapshot/backup. + Support parameters: "full-backup-interval". + type: object + retain: + description: The retain count of the snapshot/backup. + type: integer + task: + description: |- + The recurring job task. + Can be "snapshot", "snapshot-force-create", "snapshot-cleanup", "snapshot-delete", "backup", "backup-force-create" or "filesystem-trim" + enum: + - snapshot + - snapshot-force-create + - snapshot-cleanup + - snapshot-delete + - backup + - backup-force-create + - filesystem-trim + type: string + type: object + status: + description: RecurringJobStatus defines the observed state of the Longhorn + recurring job + properties: + executionCount: + description: The number of jobs that have been triggered. + type: integer + ownerID: + description: The owner ID which is responsible to reconcile this recurring + job CR. + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: replicas.longhorn.io +spec: + group: longhorn.io + names: + kind: Replica + listKind: ReplicaList + plural: replicas + shortNames: + - lhr + singular: replica + preserveUnknownFields: false + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The current state of the replica + jsonPath: .status.currentState + name: State + type: string + - description: The node that the replica is on + jsonPath: .spec.nodeID + name: Node + type: string + - description: The disk that the replica is on + jsonPath: .spec.diskID + name: Disk + type: string + - description: The instance manager of the replica + jsonPath: .status.instanceManagerName + name: InstanceManager + type: string + - description: The current image of the replica + jsonPath: .status.currentImage + name: Image + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: Replica is where Longhorn stores replica object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The data engine of the replica + jsonPath: .spec.dataEngine + name: Data Engine + type: string + - description: The current state of the replica + jsonPath: .status.currentState + name: State + type: string + - description: The node that the replica is on + jsonPath: .spec.nodeID + name: Node + type: string + - description: The disk that the replica is on + jsonPath: .spec.diskID + name: Disk + type: string + - description: The instance manager of the replica + jsonPath: .status.instanceManagerName + name: InstanceManager + type: string + - description: The current image of the replica + jsonPath: .status.currentImage + name: Image + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: Replica is where Longhorn stores replica object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ReplicaSpec defines the desired state of the Longhorn replica + properties: + active: + type: boolean + backendStoreDriver: + description: Deprecated:Replaced by field `dataEngine`. + type: string + backingImage: + type: string + dataDirectoryName: + type: string + dataEngine: + enum: + - v1 + - v2 + type: string + desireState: + type: string + diskID: + type: string + diskPath: + type: string + engineImage: + description: 'Deprecated: Replaced by field `image`.' + type: string + engineName: + type: string + evictionRequested: + type: boolean + failedAt: + description: |- + FailedAt is set when a running replica fails or when a running engine is unable to use a replica for any reason. + FailedAt indicates the time the failure occurred. When FailedAt is set, a replica is likely to have useful + (though possibly stale) data. A replica with FailedAt set must be rebuilt from a non-failed replica (or it can + be used in a salvage if all replicas are failed). FailedAt is cleared before a rebuild or salvage. FailedAt may + be later than the corresponding entry in an engine's replicaTransitionTimeMap because it is set when the volume + controller acknowledges the change. + type: string + hardNodeAffinity: + type: string + healthyAt: + description: |- + HealthyAt is set the first time a replica becomes read/write in an engine after creation or rebuild. HealthyAt + indicates the time the last successful rebuild occurred. When HealthyAt is set, a replica is likely to have + useful (though possibly stale) data. HealthyAt is cleared before a rebuild. HealthyAt may be later than the + corresponding entry in an engine's replicaTransitionTimeMap because it is set when the volume controller + acknowledges the change. + type: string + image: + type: string + lastFailedAt: + description: |- + LastFailedAt is always set at the same time as FailedAt. Unlike FailedAt, LastFailedAt is never cleared. + LastFailedAt is not a reliable indicator of the state of a replica's data. For example, a replica with + LastFailedAt may already be healthy and in use again. However, because it is never cleared, it can be compared to + LastHealthyAt to help prevent dangerous replica deletion in some corner cases. LastFailedAt may be later than the + corresponding entry in an engine's replicaTransitionTimeMap because it is set when the volume controller + acknowledges the change. + type: string + lastHealthyAt: + description: |- + LastHealthyAt is set every time a replica becomes read/write in an engine. Unlike HealthyAt, LastHealthyAt is + never cleared. LastHealthyAt is not a reliable indicator of the state of a replica's data. For example, a + replica with LastHealthyAt set may be in the middle of a rebuild. However, because it is never cleared, it can be + compared to LastFailedAt to help prevent dangerous replica deletion in some corner cases. LastHealthyAt may be + later than the corresponding entry in an engine's replicaTransitionTimeMap because it is set when the volume + controller acknowledges the change. + type: string + logRequested: + type: boolean + nodeID: + type: string + rebuildRetryCount: + type: integer + revisionCounterDisabled: + type: boolean + salvageRequested: + type: boolean + snapshotMaxCount: + type: integer + snapshotMaxSize: + format: int64 + type: string + unmapMarkDiskChainRemovedEnabled: + type: boolean + volumeName: + type: string + volumeSize: + format: int64 + type: string + type: object + status: + description: ReplicaStatus defines the observed state of the Longhorn + replica + properties: + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + currentImage: + type: string + currentState: + type: string + evictionRequested: + description: 'Deprecated: Replaced by field `spec.evictionRequested`.' + type: boolean + instanceManagerName: + type: string + ip: + type: string + logFetched: + type: boolean + ownerID: + type: string + port: + type: integer + salvageExecuted: + type: boolean + started: + type: boolean + storageIP: + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: settings.longhorn.io +spec: + group: longhorn.io + names: + kind: Setting + listKind: SettingList + plural: settings + shortNames: + - lhs + singular: setting + preserveUnknownFields: false + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The value of the setting + jsonPath: .value + name: Value + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: Setting is where Longhorn stores setting object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + value: + type: string + required: + - value + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The value of the setting + jsonPath: .value + name: Value + type: string + - description: The setting is applied + jsonPath: .status.applied + name: Applied + type: boolean + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: Setting is where Longhorn stores setting object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + status: + description: The status of the setting. + properties: + applied: + description: The setting is applied. + type: boolean + required: + - applied + type: object + value: + description: The value of the setting. + type: string + required: + - value + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: sharemanagers.longhorn.io +spec: + group: longhorn.io + names: + kind: ShareManager + listKind: ShareManagerList + plural: sharemanagers + shortNames: + - lhsm + singular: sharemanager + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The state of the share manager + jsonPath: .status.state + name: State + type: string + - description: The node that the share manager is owned by + jsonPath: .status.ownerID + name: Node + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: ShareManager is where Longhorn stores share manager object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The state of the share manager + jsonPath: .status.state + name: State + type: string + - description: The node that the share manager is owned by + jsonPath: .status.ownerID + name: Node + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: ShareManager is where Longhorn stores share manager object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ShareManagerSpec defines the desired state of the Longhorn + share manager + properties: + image: + description: Share manager image used for creating a share manager + pod + type: string + type: object + status: + description: ShareManagerStatus defines the observed state of the Longhorn + share manager + properties: + endpoint: + description: NFS endpoint that can access the mounted filesystem of + the volume + type: string + ownerID: + description: The node ID on which the controller is responsible to + reconcile this share manager resource + type: string + state: + description: The state of the share manager resource + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: snapshots.longhorn.io +spec: + group: longhorn.io + names: + kind: Snapshot + listKind: SnapshotList + plural: snapshots + shortNames: + - lhsnap + singular: snapshot + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The volume that this snapshot belongs to + jsonPath: .spec.volume + name: Volume + type: string + - description: Timestamp when the point-in-time snapshot was taken + jsonPath: .status.creationTime + name: CreationTime + type: string + - description: Indicates if the snapshot is ready to be used to restore/backup + a volume + jsonPath: .status.readyToUse + name: ReadyToUse + type: boolean + - description: Represents the minimum size of volume required to rehydrate from + this snapshot + jsonPath: .status.restoreSize + name: RestoreSize + type: string + - description: The actual size of the snapshot + jsonPath: .status.size + name: Size + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: Snapshot is the Schema for the snapshots API + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: SnapshotSpec defines the desired state of Longhorn Snapshot + properties: + createSnapshot: + description: require creating a new snapshot + type: boolean + labels: + additionalProperties: + type: string + description: The labels of snapshot + nullable: true + type: object + volume: + description: |- + the volume that this snapshot belongs to. + This field is immutable after creation. + Required + type: string + required: + - volume + type: object + status: + description: SnapshotStatus defines the observed state of Longhorn Snapshot + properties: + checksum: + type: string + children: + additionalProperties: + type: boolean + nullable: true + type: object + creationTime: + type: string + error: + type: string + labels: + additionalProperties: + type: string + nullable: true + type: object + markRemoved: + type: boolean + ownerID: + type: string + parent: + type: string + readyToUse: + type: boolean + restoreSize: + format: int64 + type: integer + size: + format: int64 + type: integer + userCreated: + type: boolean + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: supportbundles.longhorn.io +spec: + group: longhorn.io + names: + kind: SupportBundle + listKind: SupportBundleList + plural: supportbundles + shortNames: + - lhbundle + singular: supportbundle + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The state of the support bundle + jsonPath: .status.state + name: State + type: string + - description: The issue URL + jsonPath: .spec.issueURL + name: Issue + type: string + - description: A brief description of the issue + jsonPath: .spec.description + name: Description + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: SupportBundle is where Longhorn stores support bundle object + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: SupportBundleSpec defines the desired state of the Longhorn + SupportBundle + properties: + description: + description: A brief description of the issue + type: string + issueURL: + description: The issue URL + nullable: true + type: string + nodeID: + description: The preferred responsible controller node ID. + type: string + required: + - description + type: object + status: + description: SupportBundleStatus defines the observed state of the Longhorn + SupportBundle + properties: + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + type: array + filename: + type: string + filesize: + format: int64 + type: integer + image: + description: The support bundle manager image + type: string + managerIP: + description: The support bundle manager IP + type: string + ownerID: + description: The current responsible controller node ID + type: string + progress: + type: integer + state: + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: systembackups.longhorn.io +spec: + group: longhorn.io + names: + kind: SystemBackup + listKind: SystemBackupList + plural: systembackups + shortNames: + - lhsb + singular: systembackup + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The system backup Longhorn version + jsonPath: .status.version + name: Version + type: string + - description: The system backup state + jsonPath: .status.state + name: State + type: string + - description: The system backup creation time + jsonPath: .status.createdAt + name: Created + type: string + - description: The last time that the system backup was synced into the cluster + jsonPath: .status.lastSyncedAt + name: LastSyncedAt + type: string + name: v1beta2 + schema: + openAPIV3Schema: + description: SystemBackup is where Longhorn stores system backup object + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: SystemBackupSpec defines the desired state of the Longhorn + SystemBackup + properties: + volumeBackupPolicy: + description: |- + The create volume backup policy + Can be "if-not-present", "always" or "disabled" + nullable: true + type: string + type: object + status: + description: SystemBackupStatus defines the observed state of the Longhorn + SystemBackup + properties: + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + createdAt: + description: The system backup creation time. + format: date-time + type: string + gitCommit: + description: The saved Longhorn manager git commit. + nullable: true + type: string + lastSyncedAt: + description: The last time that the system backup was synced into + the cluster. + format: date-time + nullable: true + type: string + managerImage: + description: The saved manager image. + type: string + ownerID: + description: The node ID of the responsible controller to reconcile + this SystemBackup. + type: string + state: + description: The system backup state. + type: string + version: + description: The saved Longhorn version. + nullable: true + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: systemrestores.longhorn.io +spec: + group: longhorn.io + names: + kind: SystemRestore + listKind: SystemRestoreList + plural: systemrestores + shortNames: + - lhsr + singular: systemrestore + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The system restore state + jsonPath: .status.state + name: State + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: SystemRestore is where Longhorn stores system restore object + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: SystemRestoreSpec defines the desired state of the Longhorn + SystemRestore + properties: + systemBackup: + description: The system backup name in the object store. + type: string + required: + - systemBackup + type: object + status: + description: SystemRestoreStatus defines the observed state of the Longhorn + SystemRestore + properties: + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + ownerID: + description: The node ID of the responsible controller to reconcile + this SystemRestore. + type: string + sourceURL: + description: The source system backup URL. + type: string + state: + description: The system restore state. + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: volumeattachments.longhorn.io +spec: + group: longhorn.io + names: + kind: VolumeAttachment + listKind: VolumeAttachmentList + plural: volumeattachments + shortNames: + - lhva + singular: volumeattachment + scope: Namespaced + versions: + - additionalPrinterColumns: + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: VolumeAttachment stores attachment information of a Longhorn + volume + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: VolumeAttachmentSpec defines the desired state of Longhorn + VolumeAttachment + properties: + attachmentTickets: + additionalProperties: + properties: + generation: + description: |- + A sequence number representing a specific generation of the desired state. + Populated by the system. Read-only. + format: int64 + type: integer + id: + description: The unique ID of this attachment. Used to differentiate + different attachments of the same volume. + type: string + nodeID: + description: The node that this attachment is requesting + type: string + parameters: + additionalProperties: + type: string + description: Optional additional parameter for this attachment + type: object + type: + type: string + type: object + type: object + volume: + description: The name of Longhorn volume of this VolumeAttachment + type: string + required: + - volume + type: object + status: + description: VolumeAttachmentStatus defines the observed state of Longhorn + VolumeAttachment + properties: + attachmentTicketStatuses: + additionalProperties: + properties: + conditions: + description: Record any error when trying to fulfill this attachment + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from + one status to another. + type: string + message: + description: Human-readable message indicating details + about last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the + condition's last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + generation: + description: |- + A sequence number representing a specific generation of the desired state. + Populated by the system. Read-only. + format: int64 + type: integer + id: + description: The unique ID of this attachment. Used to differentiate + different attachments of the same volume. + type: string + satisfied: + description: Indicate whether this attachment ticket has been + satisfied + type: boolean + required: + - conditions + - satisfied + type: object + type: object + type: object + type: object + served: true + storage: true + subresources: + status: {} +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.15.0 + labels: {{- include "longhorn.labels" . | nindent 4 }} + longhorn-manager: "" + name: volumes.longhorn.io +spec: + conversion: + strategy: Webhook + webhook: + clientConfig: + service: + name: longhorn-conversion-webhook + namespace: {{ include "release_namespace" . }} + path: /v1/webhook/conversion + port: 9501 + conversionReviewVersions: + - v1beta2 + - v1beta1 + group: longhorn.io + names: + kind: Volume + listKind: VolumeList + plural: volumes + shortNames: + - lhv + singular: volume + preserveUnknownFields: false + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The state of the volume + jsonPath: .status.state + name: State + type: string + - description: The robustness of the volume + jsonPath: .status.robustness + name: Robustness + type: string + - description: The scheduled condition of the volume + jsonPath: .status.conditions['scheduled']['status'] + name: Scheduled + type: string + - description: The size of the volume + jsonPath: .spec.size + name: Size + type: string + - description: The node that the volume is currently attaching to + jsonPath: .status.currentNodeID + name: Node + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta1 + schema: + openAPIV3Schema: + description: Volume is where Longhorn stores volume object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + x-kubernetes-preserve-unknown-fields: true + status: + x-kubernetes-preserve-unknown-fields: true + type: object + served: true + storage: false + subresources: + status: {} + - additionalPrinterColumns: + - description: The data engine of the volume + jsonPath: .spec.dataEngine + name: Data Engine + type: string + - description: The state of the volume + jsonPath: .status.state + name: State + type: string + - description: The robustness of the volume + jsonPath: .status.robustness + name: Robustness + type: string + - description: The scheduled condition of the volume + jsonPath: .status.conditions[?(@.type=='Schedulable')].status + name: Scheduled + type: string + - description: The size of the volume + jsonPath: .spec.size + name: Size + type: string + - description: The node that the volume is currently attaching to + jsonPath: .status.currentNodeID + name: Node + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1beta2 + schema: + openAPIV3Schema: + description: Volume is where Longhorn stores volume object. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: VolumeSpec defines the desired state of the Longhorn volume + properties: + Standby: + type: boolean + accessMode: + enum: + - rwo + - rwx + type: string + backendStoreDriver: + description: Deprecated:Replaced by field `dataEngine`.' + type: string + backingImage: + type: string + backupCompressionMethod: + enum: + - none + - lz4 + - gzip + type: string + dataEngine: + enum: + - v1 + - v2 + type: string + dataLocality: + enum: + - disabled + - best-effort + - strict-local + type: string + dataSource: + type: string + disableFrontend: + type: boolean + diskSelector: + items: + type: string + type: array + encrypted: + type: boolean + engineImage: + description: 'Deprecated: Replaced by field `image`.' + type: string + freezeFilesystemForSnapshot: + description: Setting that freezes the filesystem on the root partition + before a snapshot is created. + enum: + - ignored + - enabled + - disabled + type: string + fromBackup: + type: string + frontend: + enum: + - blockdev + - iscsi + - nvmf + - "" + type: string + image: + type: string + lastAttachedBy: + type: string + migratable: + type: boolean + migrationNodeID: + type: string + nodeID: + type: string + nodeSelector: + items: + type: string + type: array + numberOfReplicas: + type: integer + replicaAutoBalance: + enum: + - ignored + - disabled + - least-effort + - best-effort + type: string + replicaDiskSoftAntiAffinity: + description: Replica disk soft anti affinity of the volume. Set enabled + to allow replicas to be scheduled in the same disk. + enum: + - ignored + - enabled + - disabled + type: string + replicaSoftAntiAffinity: + description: Replica soft anti affinity of the volume. Set enabled + to allow replicas to be scheduled on the same node. + enum: + - ignored + - enabled + - disabled + type: string + replicaZoneSoftAntiAffinity: + description: Replica zone soft anti affinity of the volume. Set enabled + to allow replicas to be scheduled in the same zone. + enum: + - ignored + - enabled + - disabled + type: string + restoreVolumeRecurringJob: + enum: + - ignored + - enabled + - disabled + type: string + revisionCounterDisabled: + type: boolean + size: + format: int64 + type: string + snapshotDataIntegrity: + enum: + - ignored + - disabled + - enabled + - fast-check + type: string + snapshotMaxCount: + type: integer + snapshotMaxSize: + format: int64 + type: string + staleReplicaTimeout: + type: integer + unmapMarkSnapChainRemoved: + enum: + - ignored + - disabled + - enabled + type: string + type: object + status: + description: VolumeStatus defines the observed state of the Longhorn volume + properties: + actualSize: + format: int64 + type: integer + cloneStatus: + properties: + attemptCount: + type: integer + nextAllowedAttemptAt: + type: string + snapshot: + type: string + sourceVolume: + type: string + state: + type: string + type: object + conditions: + items: + properties: + lastProbeTime: + description: Last time we probed the condition. + type: string + lastTransitionTime: + description: Last time the condition transitioned from one status + to another. + type: string + message: + description: Human-readable message indicating details about + last transition. + type: string + reason: + description: Unique, one-word, CamelCase reason for the condition's + last transition. + type: string + status: + description: |- + Status is the status of the condition. + Can be True, False, Unknown. + type: string + type: + description: Type is the type of the condition. + type: string + type: object + nullable: true + type: array + currentImage: + type: string + currentMigrationNodeID: + description: the node that this volume is currently migrating to + type: string + currentNodeID: + type: string + expansionRequired: + type: boolean + frontendDisabled: + type: boolean + isStandby: + type: boolean + kubernetesStatus: + properties: + lastPVCRefAt: + type: string + lastPodRefAt: + type: string + namespace: + description: determine if PVC/Namespace is history or not + type: string + pvName: + type: string + pvStatus: + type: string + pvcName: + type: string + workloadsStatus: + description: determine if Pod/Workload is history or not + items: + properties: + podName: + type: string + podStatus: + type: string + workloadName: + type: string + workloadType: + type: string + type: object + nullable: true + type: array + type: object + lastBackup: + type: string + lastBackupAt: + type: string + lastDegradedAt: + type: string + ownerID: + type: string + pendingNodeID: + description: Deprecated. + type: string + remountRequestedAt: + type: string + restoreInitiated: + type: boolean + restoreRequired: + type: boolean + robustness: + type: string + shareEndpoint: + type: string + shareState: + type: string + state: + type: string + type: object + type: object + served: true + storage: true + subresources: + status: {} diff --git a/index.yaml b/index.yaml index 69323be692..7986bb9a1b 100755 --- a/index.yaml +++ b/index.yaml @@ -6419,6 +6419,21 @@ entries: urls: - assets/longhorn-crd/longhorn-crd-105.1.1+up1.7.3.tgz version: 105.1.1+up1.7.3 + - annotations: + catalog.cattle.io/certified: rancher + catalog.cattle.io/hidden: "true" + catalog.cattle.io/namespace: longhorn-system + catalog.cattle.io/release-name: longhorn-crd + apiVersion: v1 + appVersion: v1.7.2 + created: "2025-03-02T13:05:54.056983799-03:00" + description: Installs the CRDs for longhorn. + digest: 0275645c08304471e41702164f4d08eb7484e4a5fb794fe78a43f0f750e83bc2 + name: longhorn-crd + type: application + urls: + - assets/longhorn-crd/longhorn-crd-105.1.0+up1.7.2.tgz + version: 105.1.0+up1.7.2 - annotations: catalog.cattle.io/certified: rancher catalog.cattle.io/hidden: "true" diff --git a/release.yaml b/release.yaml index 48f86f4560..a7ece68e3a 100644 --- a/release.yaml +++ b/release.yaml @@ -5,3 +5,4 @@ longhorn: - 105.0.0+up1.6.3 longhorn-crd: - 105.1.1+up1.7.3 + - 105.1.0+up1.7.2 From 0d2d04637be0c0c0477dc190b526d132abc94a8f Mon Sep 17 00:00:00 2001 From: nicholasSUSE Date: Sun, 2 Mar 2025 13:06:04 -0300 Subject: [PATCH 8/9] fp: longhorn-crd-105.0.1+up1.6.4 --- .../longhorn-crd-105.0.1+up1.6.4.tgz | Bin 0 -> 12795 bytes .../longhorn-crd/105.0.1+up1.6.4/Chart.yaml | 11 + charts/longhorn-crd/105.0.1+up1.6.4/README.md | 2 + .../105.0.1+up1.6.4/templates/_helpers.tpl | 66 + .../105.0.1+up1.6.4/templates/crds.yaml | 4208 +++++++++++++++++ index.yaml | 15 + release.yaml | 1 + 7 files changed, 4303 insertions(+) create mode 100644 assets/longhorn-crd/longhorn-crd-105.0.1+up1.6.4.tgz create mode 100644 charts/longhorn-crd/105.0.1+up1.6.4/Chart.yaml create mode 100644 charts/longhorn-crd/105.0.1+up1.6.4/README.md create mode 100644 charts/longhorn-crd/105.0.1+up1.6.4/templates/_helpers.tpl create mode 100644 charts/longhorn-crd/105.0.1+up1.6.4/templates/crds.yaml diff --git a/assets/longhorn-crd/longhorn-crd-105.0.1+up1.6.4.tgz b/assets/longhorn-crd/longhorn-crd-105.0.1+up1.6.4.tgz new file mode 100644 index 0000000000000000000000000000000000000000..83c79207959bc953212850e05909db0e6fdbba61 GIT binary patch literal 12795 zcmVDc zVQyr3R8em|NM&qo0PMYMbKEwTFr3f+6)5dHWqa1$k|wt29aW`v9m#%1yO!gUY^Um( zNhN3!-HnJ1Z~(I9b|(M*DO^Z`BtR1EZe3#Vi&`Xrb8tI%93+%1mXwi6#Nxx#C1lxj z16Rp6yL^t0j*ebFe=h$X9UV3Q9=$mF%Qwf*|N8v+_{GtSqvzio9e?}c<+tB}qn%>m zcygXW_RZ1Ou$rBFAP*#jW-!B)@RLUXL@B|>`12AaDPnw@rQ6ejp8fyrUyoll_W#S{ zzaEACe;dzlza9P=tnumuaFl^LPLNpo->t;3L`!r6{(SiR?~g>ON3TDpki>Emi5&yz zT>g$E(|DxIO+bw1m>_Ua?k`dJ08FaSFi$ctRm|p{XleQhCOP7=*J6H^^8{ zBJlEC`4g|M^7$Np1_zU>F+^hdTOoML5X=yOC5(BVBpdLr943;2iTx~5pFa8#sn%ur zOu!J`;9!O#m~#X;T_Nzl`3y0FGQ?Gf=NKh12aq9<;1$kL3^EF`CFbDCY$FHb?A?_p zi^&4;6h%+F#zkOPADjPAf;sta_#hQEQ-(=42M2%RlRxnTFuhd7Q`J<>dX1+Y;}s-u zf!O(b1LdL@0_`W5L`fdoJ2`#Y!giTu>B-^YpZH`3qiaOslfS(ecVR|9(&oc*^h^X6O29mcM|}W3}oh;PB6n%E3a5J60kak(UU z21yKA4E~Oi6;MUQvNU&OeVSDnHNY@Ur`P2^DA@Q3`0Y1PaEsPfp99aCzyCg|-e~3x{tXyP6Br?I@Sg|Z;Ac5`Z3NURj3={=YPMMGSBR}~gzS~DkO4@9 z>Qyu@mhvULuh4u|iW#7Lti7xbWS;#sb<<}OW?k`cBrP@lB2A&IAAh0M`xt3r~z=6O5B;u*}~m26RAf_e789fjUvp2>n~ zk~5e%v6E%^lCtbw1$_dNK^miQ3>dP-!A69D5_PBKj1 z3-XQFDNXVfDdE-h><>a4$Qctu&odzzXcZx)G03?Rms3X9STa%ZMWY5JZc_aKb4FKy zS0e_%ubh(iFk7C0sc1ImQw`-x0MUiiT$*o`4$m`&$-;%M7!D0gmbXAmQ8ZO0K2!xX zwC3v}APJ3;tM4~BNx%$&l%W(d6az{e7>QQS&uZAbqp?@lF~8m(57ElUj}1)D>Mt$W z7|j&qW7^vJwKiWZ>Ya;=iB_N2$1{|{W3}?5C0fA~U7V(fyn28B>D#N?Yfv8%`)&l7 zgPSE{2)r$%1fEfbcw^AaWkhGcq9~h|U{Xd?#4=oLQuP>g*Ld4N>fe*vHvmLGv7xFYi91%s5#cN1f2&zX&&xmnBQ}QGhbbF0h1{jLyg5WP@+g$0q z2uML81ClBbn1HnqY@Pu~;zr9WxB(0am>?%cdut^LHA-Jlh5#mWdIE%c$WIOr7dR`p zQAAg(oZxJ8C>aZ$ZVi|t631Q#L!*7zWM+POw>%NNvVpq#-*4aF`Agn5mWUfwG?e4 z5~mcCOxa`-EQxSFTj5MBgMa0SXJYD_&7Mk*E%thziY*m43!D>h3RfsO6;kN!&Xt%I zJ`s~JXtqo_q*+)EukoQ^=+*OiQfYt_ISXu!CONq#^oC57?dJq!EJtQDk{@l|Pzy;} zCpJn6vI7_B1k7Q=^{aeVuI2&*jSu+k_i^l7sa2%~AqIksmu$RX-6*y&4F`kBa~#(Q zc{gJS0)@9gVd*l*U)+5)K5D4diy*+QdZwef?#`95}e`#gM`l!V<>jj zol%+~NE%-i|MG&DLIzhTL##DWpeCughO?)6=TZ?*C2+J`MZ`8m6A;rIl2F(rhvHM7 zIzFJ!DP`G2?CQx{2%E@Kh#|>@e8x_QksgEX+B6n%eaNz%L&0`@qXW%jpRuJX9;TQgl1j) zUc_H4gEyya1vA;Jm(RU=taZcl_uFm|4>h!U)2)S0CX+|O$51oD>+idAFkGnS6b@GJ zf-ceNS}2fGb87V~tkgHFTVYiqaa%rxmC^0JYV?YP8z80iK`NLzcj@=CQVs06@y1Kb zE}#k-`xcaG0~|vIf&_KitpaVwAcfhoiAK&V;$;Ia{%-*{UOqJU!$sBgA*y>Z zQbBDGYI{)IAD-GC{0@P|2NwTOSp04b^nt|(79UvrSHt4_=)hKH`8t~Goasr z8T$5&`*Lu+YIs}pcVT2MR=}1PX1_%MQ+$Dml}UgeTceA)^wl%h-5Z>s3uv)94_$rk zo~cI*hNn&=x{0r25rZy6_rUs6a2Q+JZT&VIu#dKSI3h7(dWF4;lVZX@_$2zC$1z@FM&O#>^hG0Sq8T;I3I+)8X#Oeb~0D{p{nmU|=ux;SJ)=d;dJroL& zCt|P91f^vQx!)nFkbCMx$WV4_cztTUe`p5!z=8t{4lMXK=jxtV7G+j(ZGYJB)K_xKPv=NiV)13`dFu->i;AOMD7WF*sx2q2~ z5a(%+nYdoSYAkMGq$bE_GPc@`>$UIDa;%itS#vmwv2Tsj7!`l7C-Li`)Y$4>48)q| zOB90)_jEo_RpQk6Ro3c%``c)|xDk|T8H%lgIE7>Y_=ZG%eU>7GEZ6Ap+xCYR;N6)T z>icY{!9fpZusa01L$Evi0qhQSDzH@`pdt+e^*mDoF`u0X_7>VK6BE<973JoPciRIt zB)U{fP0;BcNm>9G%s|i+y+8rWiEKrVB||Hk**R7ltwIVGYj|StnCcm%(%28UbHp^S z?demCB8caltF3x^sl-kcgV{zl3bG}m`C=*PI-m@EJa2al05POur8!Wx?2ayK^{)8=r7OXi zgqU%GvL)@?38z(gL711+wS2A65Mz`L=$|ZC7>b0DMnDFy3pVRR(5z_OZ%RDgMq`TE z14dbj?}}6}VdflKa07WE<=8-6LI`_mLyP za$;8kyjGcBzPGl{YMX|uU6WugrBliPCPFrn|LuDnI&Fpa^LXcHfD&zLlTvPJ^=Y1$ zlOjb#NrV$rFki1ZaodiE5&5FN3#cPoNWcBjZpLu$s4*!^tVZvCImbB|g|SUFZ4+@$ zArUIb!ND_da8BOq!4v-pK9Zme#p0jWV&#e-A5|R9f!CboEEzkUA1~i}fC`q?TMuo{ z)9sC~3R1)1>M*i)7*^GnhFNt#rc_Q~%9k|jwxSlL-c^OP8L$0eP{39J)zg5gt9cqy zOK2q(>9img#qD;}E63NNmeX6Xm1;1zZ!+C3Ksrym&7{FF8VsYsF!~@3qah|bu-d?C z?~`{ju-d?C1FOB2xw>;7PM_Qv`1 zygYb*KDEZ$*?~Ll0eZFuZlHVR)au3guKii}*MoHr97GXJ60!QqD|r!FV1fYc@*U-= z#R2jl+(mk}_vbZglCg0PBZkrhM{u-nQ`a}VncGm7f$poCQtJnxsZ;tut0}dk!0un< z*w*#-(41|}UEt?u13;YyGvkj2&XKD4xaqz3o-x(Vu;8!??iOoNHQ?3DvAr5_8pZ(P zxtW8H^bUNaN_YwBpYA06Q=Wd1!>=Z*;bvB!9L{DvZE9L`f>c=nv97POe4)|5ME3=qF;I#ZW8jqAFi84Q~ z%T}5=h%)E(B9+-#P5)r)_&JGjB((0ECCZl40M|qba{$*6OBq|pJ=M_IJXf;GHe zHQu)4jC;rB;kmCrl%v;aS=apw2KJ_o8Vu~gz<&P??7^2En0H{__l|jQ>ktpjJ23A- z(-WBY17_aNjX%mq4zfxeFP=U}WyuQ%9wex7SwF92gZFs@Y%y6sPlmzv27oS@Xys6g zlALFV0fJC02~z0{FCA+=9<@7i&EJ8CZ#xgY-U1{2^nSab6ghf^yc9wJ)-n$Vc8zG#b)#yxV?-`w;uKZ{< zwBMF4>l-ARp9#@S`7~9(ZH^u=BukpWWmv*C2SPP8Kvp(|V#WF>De~Nj4G0MpqVH&Q zdy>M{aQu6|f@H!FjODs2f+_Tp6s$f*8N>+(a7J@2_f{PkjiXvugHZfP@V|siMhTkS zP!>O{Sb4EL=akjQ_%YuZrZy7ez|`t@RF9@TSnVo3*P7h)F3{2+`GJXncq265XF&TL zM|Ui%%5R1?HmCV7&L9{tq$+H;r%G2f7$R5ce<8<@N(SG^O{7^9ZiXJ8)ep zFZ1??JU>FO=E`Wy zF$()Mc<=1ss_vR`eiaifg=tUx*Lh^sbzapttXdz!2Yz5xuLI9>s~&krD;WN#HPT`SczU`%OxF>ZVG;{wS30m&AS;}Nyja&l}pPZ?iY&M|XJ)tp#-W2kx6lu>KhQDC=dw_<&uij^NN>?e&@C+w7 z+jtRsOd?&kaZc&H{h{}$Qef?YwR^Dk@m{^a+5>AJJUxN6KVa7G+V-9Ldf${F@M8Q*Le@jx1&M zmPfo|w6=W0JmT2$o~&1M%WG+<8jPvKIooxVhc3$VnZ8D2A(44nR?U0Ac3?1e_$N9H z!mQ}5ItF%$q`cwT3*Cf}yRRhM@vOhbLc)+nX2j0a#_$|{4wE%pppkP|TwrwpKaVkW zSGDbzEfq(!Fv(s%_Zga;tYCTp+4U8H>FE+;a*0-SjpEm2#2Dr2g25QYmv_JHy6(T~ zauIagXf<+>w+o~g8$&UWkI#(DTgOjQUwndsVoitKGkC@0xDIt-ZTEePW&`%Ur=GqG z6bB;GeM8{TM(m=%pxWEJk*#&3gceJ6f2(M_H6T=t%iYW(=BEiIm@K+ma5-1OPFCa} zb}5AbsUCzvfK>Ad0a77AYEJ=DhWXboz*JSdElGF_daFGQyVWa9zlGPh6^201K&+O_ zz^}e#TDpq!*Pl};lM49hM}msTszMumZ5L;{Ob2H5HxMWGbRaz~XboKJ zkL*&TR~O*-hiJbpoP)a7DwEE36L z@4s2Clu`x0m@Hf}!NBIWq^~$ZWE*RSpsKnf~pwyREWMSxN$sOjkH zOu631(=K~{zJbtlj@Y0ncVnbrPxZwRI$^iHMph%h@EnQlHAhNsXF!a!RS@b#BJ^>Ls?vKxWfs z+=?)MQbe(qviwsEMnbw5&D8MtP`&Vvr*0vFIbb;~)arv~Xv6Ut8v)*&R_{>okuwWZJT?!L zi&6B|8yzoHbWyFuJzDYGTX1+?F!1zS_3Y{#T=fjFpm*r?-HP&}WQx2Jx zu4v=x@$*%HfnFLg)M){Rj0NZno@+MLGkMaHd%>M<)WHoUm}hR!*WhMS%CgtC^MKW3 zcmTg`pRa7f>vFvo0IxD=3qji#$U?$$(oZX3i?`DkaHp#o44tB`0N{a*^sMncd6x$m(Vy|$9wOt<1HQ4 zRrsNJ)rvWkv!{mN5@@J8QN)`#{7DZ9-3a< z`Z28V{Lo>}w1+XOXCkvG@D0z<%2`Av%kD(4E62kcN0~HeI1?e8Ep_Iv5u9o)9$J>V zL|V#nv@^t3-EXJP;KJ!~aVDi4*pZ@$E&UwmvpaWu957K`Q`E?*cKZIKZphERYxl!- zh3;C1+BwLb!|NK@u>rY~xOqq6`p~yLqp#(>`4YE~Hnk6-kT$jXgtVz4ZR++BF*d#> zM3{YNzv_>j=;6#m0yGBFK=tf~5~^pA)7ytCcA~gb+UV7R9y)2kdQa5S3+rymX+e6w z^wSIXZdz)=y@R5vXG^-Oo)Og5tJ{46BD+ zHc%<0Tj5byT#E~4Tn+gJ%nb`?8WPO3n-pYPvwgLOShcoS)mB5hfS>WoZCBVStgB)g z_X%xJp}q_)I>MAXQw*LiQRI}0x`h!bgdm1#j3e2MJ@Yp(#x8~#nh56ZmODpWtMr9> z9rq0(TDKaaMOnIpWShihKgbpoq%xpLy=;XPX=rMGEI~!;P<0hlM2oifkd(}1(X{GA z+e@fEe%NW!5!L1{Z&Til^X-QcFT49q;~o5Njh2JoE%@CYn%_aTRRjZ%DBwDUi7)=-VjPb~$x z2H&YBvtJu}vRQ5S+VU03xav11i&8g|BLse2A_6#)cjX+!Xb$rvJ5Yte4NelV)nOb9 z{zc8(cI1o*C6fR`^@TmZ(wTmbK4YnN>Cz4jSwg9Yy#62aRi9dZrPRO~l1z)v!GXFS z=KxR!4hkFGfdhI5`E}hOP`wyp5QrEh0DTs^kW_XnwWyj-IV8LpgxthLv{b|7w0bef zG?A}nh=~CxuT3~qBOxdI8lkjgOPv$K1b?lga%sM58(?kYLWxf8CVMZ0{G5Q<1|S$M z)u{cdH0^NHD7hwea0VjGKrGg z`cq$*!3Y$LK*0#~@QgrT{eh>iN1iEVm}k}R$(*tXP1L}6(px1IXw``X}rfQNKQd=3X;>;AvrlWzNZtdMh$8ZIz1Bw9UkCG zGfGS7@VZ!71*6h@%H@1=$= z9U0LZ3Q=F#UJ(&rwG(MyftE$akFA_a)h#lnKS{o|xRMk=H4`>3lKNsek&5PT|AyE? zZ>{aD`mH&8yqB&Xn_1+N*+LzLHxymlVswP%tox?_EjxiVCAIyUyG}R0PiaA ztr__`Dk(|OF&V=yMbYa)vi4u5?dwl^p?lBemYMP95GVHY_x)~)H@dDM)f{Ci#s~tI z6Cx;d!N}+GWD8}@?^^K29ON=rvS5fgN1{YglQICwMjt@2`9CTYbarEXfTB1LBw*(Z z0UAjGD%N3C4a}bzFfj)SzDCJLptFQ)nb&!qCl=sOvL($IOOR5|@hsU0YL=j<>UbS^ zRW^Bpvti zl2mz|AwznWpH6EXj}in04W6O7;6G4f6N{nVc=f|x7cd1g6hW~9aD7R&VwB9sID`o!p>!rFUg%{IEg@O>ISZGN#X_rj zHJ4U=i$}YwGJ;9A+>F~ze=jN*eV6MOv*LJLwM1tqqAR2_pda2aoT1tX12`8mQb_q? zI`zy>D7PSAZQD2Jc$qn47-fQ)q!MbK^;=%iU16_N>*o z1%7>pw9(nwhOoe{$uxDyQm|1=2&)-g;W$o8NCk2B+Yi?DSMHGd0^Z4XXfh8A0)H%# zC!vdx%7ZI?MrSaVTn3jYW1CZ&+wNEGil|~}jX9=7Rz>Vg-?rk1wia$jcDe{Ix`3ZY zbik;6g}+#Mc6YkCj*-pD3Z@s3U7uloeY%90T%r|Sqxdx$F-B_fd26Gp+D>~mK4eOn zo<>AV`BH-+cgh?}-g*5QMY+GYlR-A3l8oOte;*RW+-+>HKI*bf zZ10t7LcuCyd-dB^Y;OTj&4eYkSAQvEdwJRX?Z@^iw{oEs8~vzGOF!I zVX7I-B{;CE#lN=$*ZGc5D%7CLvjaCo8jzeAXd_Dvhwg(5_fLT{R!fKMP#c;cK?DgR zND%j3f(R$`0;9Q4`e|S^fzb?~p1^1xFr#s9e9zNbHu9_!Xa(iThhvYE=>{sp6z5}~Wk?MFGn~j;F&al_$*KJ!( z0n=@#Auw%PYAPW6aBHhTdM(L{-J`*Q84|tc)zN}xzJ(eQ&@LA9Rj(Lb%ykvUENRgM z6M27ch02W(tl%}WWq!~p4~+Fw!|1gAp%1U~@@x~X=XF%12gdSfQgNP6(jO`7>a>pl zx|3upWMvy4=to{h^|JZ89W^s)g{>AT!&L}9!K-`)IQ}B3lAhbbI;>D#Zek{=mX?i- z8SlVX_U{URX(HTwKSXnaQI^A`MA95!x4zZ{-3{~psY=EQ5*=2B%V^A!E(jea=tjj8 zbfcgfJviM+Z{>cys1)(9YxffrPntw8T?zi2)v_Cc~+oK@zwXyekt&3wX-V z95E&{%vBCI!xg7pbsiZ+Txw~Xftd}B&`oO#$=mBXW-W!}4t)rPajXLeb5zc`2vQ*Jb&*4aCqoSk*&X*U3wX? z7+o;LEgP@XXylohBUpEC*SaHPsq_uo+ZcCbJKtB=6B@Q1<5SzTW5Rb@cKEDm)iJ8= z$*7}(%yb+@DUIn?opzo2cO8jRdpE?kQwMI^iuPeiszWRD?`F6oZbW(h;xZwx5#dt0 zhK9gS42i4=V6UNb13BOu63KMY+U^h~InO#m>P4ehvQ7iPx9txtBzI&tG8TP@*{Igl zU^S|@9IQscYV_c&M#jGPH5xTpXz{oebLBx-Ro>GC_ugdgytY}<^CFx;6Qoo&X{k|M z-;C!ILbHipdI!(Ify$??Zd;CZmeck%%VP~jqfId8toU1C{3j+DVEPaW2AJj(3^2g} z(`kSipIx&M)`yrW+{!?^PlcsM2mlj9Ul`Qi1OyrvW+%w zsLpr`=g}G{|l}rwL%{ba_+HqY}(P^_GJI`(R?aAxWiVQuP zVMCv8R^5q8eeZPK<_H!_ZPjln;j>kxLK@bt`bprR>IPLesJahK)ol_0kE|0`;#@p# z4XPq7A8>SyvMmmn_o-mdxYAUljO(;n=uDack*XrpC_EitI9Ot$Sk`Typsq~c6DK`1V z6nxZ4tztZ%BPK>jteo;cqim^U$lKc$I~lDpxDF*b`e3Ht#dU^P(h(P^0obIF!4=97 zb1G*;7x_SdjV}I>s|elVN*S%ilBySN|V-+S}FqHLUCo+j@sZU43a7)Ndh|S5NNj?N44ZI?H)R z5a$CyRuyV+FPpCi9s7)yD9#fU8{+sdEGp9ZkH=*zkAM2dWA**S5!+1<6Toh$_3dW|WUKvj2BT|4;wwSv&KO=J%Y6#90X!26Ig+XJFHxGnNExlw z4IaN#63Q>r$G&)AvT&RT?x~okr*tLummroGC|gpCsns=%gp#(8VFHpbZFBkrEWY5> z2fJ!Kh9k5-w!Qp|FW9#A|U#rc_nG3 z*OY5K-!Mut)FkAfXQ#!OUtggFMVamD5U2ON(*@!7MIjQgP3n2C1kgIckmK=>jr|BL z8&V#Y_uPwu^|(%MbysuDhik#j5*l5{Xl?m~dBm}8x2{)n%j<)7YM%~F9oad1GBK#g z6BK{%r0w=x2YA7tywk{U4XApUl6Q_Munw56z_Fexx3@2pBlU;5Sg|;Qo~bqZwlyKUvyd-74%6}>BtrU+HP$B zv2{&y$Ef!Y+{i)O^>|TZyad^~x8wDHDM2I0?2C*Z+v7qL0Pf?!Nt=n%vMy1SGg0V& z=xi7CX4j~$vCtPz<%RC-OgG`jq{rtCw;vzW_W+*344ww4y_++H)@Z+HO_T3Gbwog2fRWw_e3oxE0|tDc6~))db)&|IIrxxTYkS?c(#8I z126N4y6Jk?Hv&e9Ak~f_&+eFK?z}X%bC7jqsl9%3MDGu2z#v)Kj|T~m(bs^t1DjgnL%n}leLe*+5DT@wqp7>eQ+9KkwKqRNK~AoD;Bs* z&Ma(e!>`z>0C4Rq~8ar~M@f;If zd)$ClVPakw^Ce{HwT`UtuX*Kpm)QNieeBUU;rT;7)j=N?A6~wGb$0Q3x{7xT Date: Sun, 2 Mar 2025 13:06:11 -0300 Subject: [PATCH 9/9] fp: longhorn-crd-105.0.0+up1.6.3 --- .../longhorn-crd-105.0.0+up1.6.3.tgz | Bin 0 -> 12800 bytes .../longhorn-crd/105.0.0+up1.6.3/Chart.yaml | 11 + charts/longhorn-crd/105.0.0+up1.6.3/README.md | 2 + .../105.0.0+up1.6.3/templates/_helpers.tpl | 66 + .../105.0.0+up1.6.3/templates/crds.yaml | 4208 +++++++++++++++++ index.yaml | 15 + release.yaml | 1 + 7 files changed, 4303 insertions(+) create mode 100644 assets/longhorn-crd/longhorn-crd-105.0.0+up1.6.3.tgz create mode 100644 charts/longhorn-crd/105.0.0+up1.6.3/Chart.yaml create mode 100644 charts/longhorn-crd/105.0.0+up1.6.3/README.md create mode 100644 charts/longhorn-crd/105.0.0+up1.6.3/templates/_helpers.tpl create mode 100644 charts/longhorn-crd/105.0.0+up1.6.3/templates/crds.yaml diff --git a/assets/longhorn-crd/longhorn-crd-105.0.0+up1.6.3.tgz b/assets/longhorn-crd/longhorn-crd-105.0.0+up1.6.3.tgz new file mode 100644 index 0000000000000000000000000000000000000000..58707c7ddfed7739f24934fcbc3baeb49e9291ae GIT binary patch literal 12800 zcmV+bGXKpViwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMYMbKEwTFr3f+6)5dHWqa1$k`l*xM^&j^N3x&MuI0ES+o^hH zQVE(wcOzm09Dr=OoymWH3Kx1JG=mwYgr7VDAc7f8=wcedEKAT7)58d{49_u&PXL1?S|VmG zw#0Fa$O$;eSdI>?MF?CWp27&7fO6IG4bRZZTAZN-L5?P(no%QS@gtbxkBD(h$q85= zKZ0p${5yRy{pL}Oc*Jm;$#>_3XD~@P$d(A4UY>Ctyo`p5zy+ob3Oz%)&8BuD4b zx`1$e^zHO$di0-pszBZK3~u+-_J4*}X#z9E4}V#rBt?u*vvhk}(6j%)`R@2dWB90FE*+#|aWk|NE5~mS~Aiz+Vsl_~Vf%_2|{76p~nOBC%rt zoy*^mWEzijxe18T91{c%%Kaq@AAm{q8Rkg_ri$6T6)jCa!X!srmi%#z7{f6F{{|V$ zNd#VeBY)!6RX(5NPvBruHHJtme=7t}8G;!Cu!J$slVk(_mBU0*FtMK{>eEL*A=SDp zp9vVE8yw6~1apo6rz-^hH=iL!P=>hb@EoHg<^VDT61>70ia|y}w!|DfnQi1?oV~pg zWieR*o}%b!*SHAm>SOc&NiZkh42{`=gqjInlI70~s3q%kTWLz#u zogMR~t(ga2b9Q@}2IQT_QUK;_m3ggLaqna(&`W0ep93gupEMx!@ zp?VdKi=}+Y?khB3mSP6zUU^cc`9<&HUy50+7A&5ZOJI@E8B7YPN7X!26^mtI+2e-? zqZ&X7uPDYrdjmBnYSp8n3%}$nv38?ti*%wtq@sZ~C<%;nkf+VbY4z&xuaAnJiTzP5 zUZ4d|P|B&cO`;3^QWmm~NBOlysQXLQW~sJPW%WHg8X+IkEu$*6r)cWBH}+jz5f3dAv}I`jY)h0PII2o)g|IIXAwFR`vFVM zXoWHu!wd@jv7t@^5K)pbnk0x#7Klh9JIiqrBUYob>!a!Mx6>n`2nrz%Q}Q0K5YON$ zJpm+7l1D(ZE1pt;Y-T0w-xjWNR~4k>yMZ$@&qzh6ORDk5fy4~Nn7Ga0O%=^ElvQ8V>!t% zc_+v>Vy868SEPhj)3e_TZ6Ie%3_Z_;WS~`ql*SkdJ9==hxbNxu|z8E+$%iULVg;29MRskCtc!PjqpbBJ%Rx`NwarYOg_kMC`i} zU=D7Uh#~N%kP>)C8RCsWGnWya{f44!T7pR#O%cm*u}Rfq&|Twg1F3&cYTp15{m>$) z5=fMYulFp9b=TFt!(7PI3~@vhNfxgmX(6Z{Aw46;1x?A5SkUb?Vi{m4q6>mQmu+*U z^CBPxg$zilKwtvaLa=!TAc-3-uiyqSBw&J^811cLEWlJY3+c z;6@Q$t#X31&7ov0c$R0B@xvIcQF6%fVggyT#2JdRoS{RQ;)(1CksN8divNQllYkaa zYlW&uQge^#5rkbV8K|35U94t7yb?oq`ReLDC@@hor6#2++8UQ)e#B^EGDl3+lhjhQ ziAbDMOfqGYNw6fs`D}$Vu?+r|Bc6$=Yc_i-IkwpAc`CM4+$?ZTz$sjzwv2 zR`^6r!l2nQ<&b7!HN3`$f}vN>r%9y&PUI}GHJaq)n$R0EQMR8Gkg*(@%}9QXkS-F}E3^YFA_dmw5Z>3h17K9iGGG4Orf_0AiIJ2wWO@Rl?1`|sw6nYdj<)gBgRnd zsym}JL69`QD*ojKFNF-QP=;7*pg>Jha}8%t^UkFro=V_ow~B~uiY6eYHzc93Ne;!Q zJav3PpHj-QiP+VXwGcLur4U1s3Hgkj5F$>QC51kMuF(h1GF z_PvNdTLy1V*$QT|S1+D>^;qkM=kK=NARcOH^`=`3olGW=f{&qQg4f@7w{DRexZoGVG?uU!2>qAuc zVx)rF9@O@rwm&?zJ@_30iw`XRp|JSf80Z6w4=g^g_%DXV_tAl^%<^?EsUEjsab`fj z12gpP8TaMjc-8Q>=9RD#PkY#8OQytb)X{}!(?%Z z=7=E@_4KO~EvxxkJ>5p|!4T{okbyn5yP5`8USpQ!FuB@uA3I3wHlB&w@*s`z1_dw2 zgYt6N-5W~wuh<9A7|hUOa{_)svn8e1^6icKT@17mIZr8><3%<3Tpjl_S3~n4e+g`I zW3*nC)!7Klb7hwEUDKlP>Pe+idAL44)QuiiaLi(qWhdZo-yR(oy(mjvqBTZ09}TAn zkSeRGVOIYikMats$+EhGI{iRh4j}c(>i^k~>+nlR=Vv*m*6kmg|hp6~F z3me~iEbX5*aD5jpf^B^R3fR6E=WCp3O!sQqPas$3NqKMs7sA4wnfP~LrQgC>y(crU zn9nzmXP0RHGTUl8_Y^@t%6`1#sC&;7DLt-%+V20@5Y**9egEO7EgCJOu+!(Wq_B>_FB~QwBN2i z+(4YCJ!ay10jsgNfsvXZo5|Q}Gp^UZL(8#JVrR|aD8{}uPGeO3y`IFcgHmIwcQFua znlDidGThVoJXMKP<+>1@F%c4)TzK$fq;rM4Ak>X3B-JMBG_AKvrJ4(=T?-PGu~|v z*pTQ_Ej2->dn9QATrdMcPxJx>EGM!RIhG8qXlCbFZL|t0SghfR!DFgtkV<1e;LZ`# zytb!LEs7wXbFQ}P>7^1oQ4D4q*(k`CjOL4_pzDA#@Zr4OF#yDnik0R-*_H!==_++} zCuUD}W(#R-lPxVGUOUB<4+pHaw&dwr-qvN%5Xig%b_ju9c)0CA?Xx?&sMWjX2b8V^ zXA)w@15hW2$P{Dk?=EQ9~9!BJg`Yxc3Y$5&jN4pury`#pYEU_BB`{f+xU=+qS)wE5- zIfX>1AO{D}z`;3rrw32`C-_K$G8Bt{UWt_}etb}IGzVUDnzLl=bbh#e;{hsIR&PDD zIZwAYzA8u!gR8^H+F@8#Um9lB{g_fYfhk|otlNrOlzLkg(q_E&hd}{b1yoN1s;=f~ zNG+k2RHV~_SQNM0O|KkZhgwc=!B(ol+`h?ly8!7t?KYDJ!)P#!2E*usG>nFr=)h_N ztG!R&$-rs@s|~F7R_5x?eUKykj`!ZvSTdS1PDX>14lw7`__mk1Xn)?!+x1^==i3|S z&-3!&`T5iuYi9@Uv1aK5FlsVv6<*v+P3W3w|<7hlmnk35n zxGr01;vmYL*NaqUV>SJQt>fn;#*xsvZ4H?Rj^c3|FtdEYzcy{$t$Fz>*; z2Tf04-Vd00J2(C)A34Y>b-Z}`9F-+69C(nR#%2Ayk`3PH4Y0*z{X7{4+ZzD7V4{^n zElP5pAqEISu_Q>PGrV-H^?20o$Tfcl9=`27^m+@7^waz8f>Pw@8S+vH0a(jC9N@Wg zux(=H$k#ayETx!}13+$=YCVJs&lUTuVMhE}69rM+WxhPv{j z)zE%Zx~y-IXnrO{Gv(7%{kA!Jz>q9y0+(S4+Z+hh&;VK46p9t=qol}lCpI7?REWN# z(d|hJSHtn|`3jN=Lok->stBggOH#1<7-bMA9KadPwcJ~EU^I?uT@6C<1Hu0iG8rXk zazk1CtYYQG@|;svALGY-XPDYZj001v-%&l9_F%QE^jvFl)4M=Rf8={62I95Qe4hdB za~$2V%$k(a(yjNK6cw0@N`vvwLhh)4B1-`JXITnYazddv$pzOdgKQLy!7cmxtHDn>j|^ zx0ctCY-bHD@^E_R8}Τpon$TPR8Lxl2zDfZ));F3d*Pt<|V5*l5Dh~~u4eR#Vk zAe*v{fW7O(kA=uJ$R;eAaxsLJu;)31rocHCtoH&HU@vHl=hA`Wa#!`ORe4-NNtr97 zF~=zE)8M_cgR8o0#`#rDv=pX2@n7bVRo8h{8&#ijo9j##apWalu z{b>R@A3!yfFHu$jk*Fidh2ZJw`Y>HbV1`L7m|f|>a)~j)lXE{jIcf`bT$NNs zwYDJ@wxDoCZI4IPUdhR^-8^M{X*tKtDOGb~@r|M8RZ~W--MhxFOwnIcee({`ePj}Q z)8H~LcqxjexOJPA&ox$W^VJM7(Y=!3fSea*gF)S8XnrbW<{A!{^_T6W12(Ijpf6H< z@EUGe?W{TEKQ!Jd49a_?_jW1uc(0kUFWi@kUS-Nrek^Y(|{qe_9b2iESv+Q)nK0&5Sfeem=I*8YH5yKCEfy7Vm6Q9W+Q z61Lx3x5DHNA`3wbkB3{bTo?Ye5gO}xGsni;@it<3N>VyBVN~@6&Q9rS zg)Pq2j(IV4R#!#)F;qe?(fkUN$d79g8ly9mCUmnxB)fp=wr*29c6)JUc66)IM*Zf@ zkp#6XU1j&u2#&wH<8Qz2y={(YDH&5iYPg>qo~I6{lls!|IrTdk_i#`v${CZ2S=)T& zw4~@dS6kb!WMn}ZE>Z~M9F+dXrV&e2I6tewd`n{=keKiclBl{YcUYH;Y8R?jE6Dx4 z{@nwiVgj_O#%BV~eNB4z)J@fE#tH_kV899ntcPd7`r>_4g20RMD+yT-c^5oRlz(Lw zP^9)uG*f%;!(9S<5A6M}TvdU+2lgJ=`>o8?o%^Roxu$B3b|iR0=+%=T4km z<1CMO#b|B$gn7iVaJ?rFIy^(Xkn7Qc&B2 z)#W1SxY26lAa55)F*b%`ARnI@m$#0eq`vqB1;v^Uxo7Z-$8jC%z}oKn7R?6idrv)m z7bp%yr2B@zp^ex@fkCymcOzTtMhPvJ>i$;Ic56VW8kf77Ma)kVN-$Y;x8QQFf}O0$ zKkZTq0a85(g#fAM69S|{fYhD>qzv<~Ux2Bqcw3V27W7to7%d~VA=dV7cP$m`d(~krdkyV8@`pPcObeRs!>aQVA?CC&yTF@G}*2jHq7q3wk zEq(REF+pMSXuFq|oaStC&xKIT-{ov^*OKG?6Z)76MZ4dVw^I$`QuR12h4xaABYZ() zbRXHJMz1cw?+?*_iSW{ako0{PH`qwM0T##uOp0oHm<`dES4zZ6#tf7y1b9Mit4J1C zUO1UjjwmN#qkUR^#@W*;c)!G4I^TqVA@mr`0jDb@Fy-YjB{16n1-pt~rdVHo=DT-v$*uNu~WXsLV?5WGeJy6cKaB&V zXnBv@G+N>$X2@xu7z)SiOVWf14yor-x3}Q%x?texx9Zu|Ik@T>U_tNR)1FOr8PW$f(rc{mj;0(k zD_zmX)#K-@00X@=V5rjq3>gd189di)sAuw|Blm(k-Kc{bN-)pdp0B~pq?Bc^Z07;1 z$M67t(>`C>gxBSIEdX9+&=!KWFOY?V<)oihz!q<(FW^pBGZ;EWT>-!Y8|hi&d-5(7 z97IQ~1Qz0a0t>M{frZ!`3M?eBkVZ3qb`}zNhw}-%!}bK;VQ(n#j=(z_&D?L^F)Ss{ zdEHnAAc@O&h5FG>l(Pk2@;lx&>X;UzpEfVY8w`v3BPxHJOBvXERj6alNJ7Z>HLLpar)X4wNMI5 z|9E^UN&}Vn<_&8vqx~8a+Q|k8eq4z+WTJBQabuww&qC2{kP!u6qVc}8E!dGjT1A#G|OLLqHx^9gBFL)z5sBVufP zONcQ0&VJP&JJG|LhXiO0q=D+$4JB01Ag8wvRqRA@r?k)C0z`I2Z#|G25LD%n)XJql^edFT$chF&e6U4^ z3~ZoMO1HwJu(%c%%(xoz3z!=g&NL*LX*Vgzv}XHq4Y6u%ud1zvb^$-(mD{ecQ&?BU zH0~4HoDssE8JA?;$Cf$)ai1 zhqjkceSE*uq$8@$UEZd=8|T}PC0=&-o5nl%-5MN194!m=smRMNcRNoh;aKSL8I@a?L^vr{m?BT7mtNQVRs_BW zN2^+E=OucCY$~5tTMu*$$blEGDP(YkGQ_qplXXgRtx2gMT6;KL6ddb9(d*RPi85xX z2A@bDLcu4}e1cCT_(b;O6Y)P?6}0Cr?YUnaW+=*;7}ekCY#XKcvS{aj=&Yd{o1a<= zat*#yO=iC}^klQz?zQDBlyTK>OcteXBu5DRv_u4OB=5>Oh|wJ8Np_$LgBzSAVynYA z7W|8vx9!Lo5lSWjgz5`>exoz}9(}@6?b4+k8nT2^4|)AR=Bqxn{7R{TGbEW7or42) zJ*|TxC00D4D#!`L7;ju#2^qcN&xyKbRntiR%%f-opMNcGYGkfiD;>Y$!Yas zkZB@c%@7jCeyvkgEn zTB=d|O>Zj8P!yG;O?^aK?`^p3Fc!MG)KV1T`9>QR1Tk`Sp!QM0cw@fmwEK)d=wuQl zxAmvKE`t#$7=eNj=;0ZGzW4)AUyeLe$}rEW-;+6I5t^ubn`$4T1VNIgwRbT}kSeBS zqw-h19Vs$ZKKn_=@G3}7L2`N^lGAvPS&*E9QFGF&2ZhTKCT8$diAar^r3OYQ% zlV+5b(BXBlunI<{`IO7~NbxML61V~KIo*q{BC1oC5~^p;4}CZ^`agU%j`cLxNV>Pbc??x|dU#sfMwSHU zXF4*XHx#12vb`cAzGx@Xz5*?aj2~M$m8x50On;JmYjGthfNCaeUL^I!a3U4W-~J7; zh2C1*S@m0U_INK{JvOt*C9}ieOxulsm|y$B6g3(!&#;%_q=qMWL&J8r z@jz3Ko_Bf0ljppji#l~Yj5oKJ>Si0SOF8QZr8`Qm+h-sy1>dw_rDfb2?5?! z-dQv9byQN4pkp$IU5cXDgJkW$PTSX?^g{QZ%PlkG%^^{*RE!Y> zEGI-z=z@{Y<;fPxn%}kHjXB6=u4KUwbB;ubq9$bkl8ruqV)K7gDCq3Q`T#|79!S8> z83Htt0#vNSs2Z3*Ghkv45`2x4jX-A!*D|m3JWnjZpJYp#FP0#soa0%t5!5U}Pu1}{ z@Um?324~9(q!_7H&Lyv4(&U>d?gIg#WTGadtowvAfHM$Tvrf(=axuVSSUF7A@>J0r zz$B^iI75c?EI*yrIvynm3K~2^bHRV0#wHe1r5iIUtgQK1W=eh$OcWA*UWF<1f2`&> zV;hMd(ewSdlpLUYQ-p-k8ubSMndUKP`uE~AX-AQ@N*U}A&Z4p z^Kve&_!f_LS7ii~Y`Gb?oBm!@F8VIlFJ{H@wrYvaP()WqWk5f?VK_sz5e9HBW~7kv z#dPYKomN0B2spNoJmSUkC_n&*i8>7Ay)sq{zQN7pdJ%=m3iXbn^$P|1aVkwj_p0!#c zXf0N+np_*rZ&jd~ocsh!E~1w)Ej9g8#w-`)W3JcJYsvun1XpQ-%=Ib=b{}A|vS1=F zArLD}Z+&?S8YYU5Eg&XS@OOG6di1QZPHNqJrfIxrDWa=XuIr3CaHy8I*iI-(LCTO2 z_(3dI4x@RcMN1F3paPfxPUTu;L;!{y@oBqDU%+Nb%pn}R_FL3iOy|avQkT1-Z0%XA zaSQzV4r!yavkhT^U6X0*kfmUwmJn7my25dsl#mMI?6)7R>#y7)^##0>?a*W%76krW zB2PjWBb5hN`i#zCEV&FWQN}i>G`HQa+7(g7&>C}0iL8p)nZ9ks4{a^nj_h<1Tyz0H zjp%?;`wD-y@a*n%aUCO@lNC%aAiF-p{Q7hWF}Xx5x<>IUGGdI>;`7!nLBi@=bj^lLS$AB{H; zA(~T9mOJJ`_dUd1gqVvEb8+uuF67MEN;aAmLx-8kyC=XTX7?x(^I=iq@zHOA5(i2g zDDkb%)h$!vL8NVZ%f$OZ>qfVK^#or+hV+N6R437n86a-xPsXRV5@o`7Yf`JGDrHpL zkHS7f@(wT>GhoGP?-{eVudmFF0aX+wl)?KdBvS^?#YP6J z0zF5#VTUJrc#5d4ug|K_aY0FZkmdHs1`o+&1lTXyr+o)@n;aW-qR1fj_PIebvtTi(h6HGQiiJ#dV*K^3UK^cQYAgNg>_h=y4=J}P%SMR z88hC2uk7Cy{@g^k`F@Dz1fwj6Nr|L6z;1o53A!8R{Zo~U6(l;W3YXECC0!6YOwf&r zC+J2&H+pcok>1MvdQmCjU)l29b{ry*iDrvRJyNQs{iX^;(2YB_Zdah@9VCwC=A{&^ zI)fsgtx?m8GmbgWmkpGeY?0pY<-U`l%a{YaTIHEMOHe<9ZL4{yS@>{mqU{m}$}Qa1 z+(s+5#Zn)l)Q(>5OB7vmTbhxs0QDtKVumcICj8c_eIIPI@JuPhFLa(UYRNm(d31G; z+jaa1tRTDAhs|yw{v9&pK6U3fbXZ8?e&`uO^0?z{j(GeXx0iFoq)y~F{J}VJyT*w; zO)1M}If)arm4!kz^n+}uX{Ip0wQUtO6r2W&S=F*(vM}r3Ms$gS2MlEPopn*X90=qkm@$mz=F6g!*l4De`m!os1AW$d{~)wwb76LP7HhNKBu+tl z4%&0jo*$a_Z0>wd*J7L16^~oHFoAa~g98b3?`Vmq;1UBoOihMUJ%c20D|lBXju!Bg zp*dnqW|*rSZiXvPyXrhLh`7|!HUl#o8ljuk7LvEubJr zxV{nx}3YnI0vj7FPa%vtfb!1zy0Fu?R76bvxUCm3LY z0jARcGd{a!A*>HEQ@E9ZcApAMjSv7PhQ2VUzYCn5($xwN!U_uVTvFu1c(TA5h-4dW z+{Qa4O!Z*^Zri9ZV}^8m#|m@RP%D`n^qO(ZD?$5+b5_Nrl2)5l`*@YfnY~aOe5$Ig zh2D6xT7iPww#KZsHC960pK(pY z*tLP{{sj@4^VDk%Dn=!kgX%2@b5Jk`Jxp^@aX4{|J;qx@hK}-#InNYT~=oAAx(xl@zw!x;;hfuKTG@oG82{xVm*mQ17xz;q&PrH@^$*`zW zExgn@(TB@7`&8#^dWQ#~phMrP4y~L~Fw0=HTuE7Wyc(^tfxIl+YG~5U&n;!Tg^N?4 zUc-hy-K@G3mHOW4xXlqPl-jD_Qo?7eN`*A6UGcYzXV(?EfOI>^3_bHXEWA1l*5eYI5J=s zqFZeQ-BR>Bn&yJk$m{7Uchpp7b(&C;Y+QA_Bd^ud73`}XY&p(t86+W)rBiJ3 ziz)b^lUl`iK1WQ9kXSk8e@59-$&k0VD|RwkV{jcxa`eGWzl-Y(ucRX`Py?_@A%iQF zA?8%hhA#4f02^KWF;#6FU@DxnN?Pl7XGa}s5a?0Vwm-KpKKF{8W3jAElBENsidEZ5 z!8$u|3&~Mhl-Vmu%8rP$0%}{ByQ0xu_BqR_T%w4w7(lX72~Bk7Kemw~2L$?&4&YPLDP`dLY%yeS1xjW;-^6q;iw2Q!37)qE#@uEc0A(MmlNLtLT_VtFqD#EXJoA9)=PGIr^piECxsqih5FM0X|$GAL>RAD>!B`%CZyiw{MS* zi(ZtaF3}pJn~#R=SuKCl99;c>>}hXT^VhJlJ8bJ67IpQdVNkz?TwXo7v$sEa$>=QS z89|&61X)$6!M$w09(3$8TB0~lP;7|f!?37G=RY2otvvquACJ}d$3NExr6}Qpn~{;* ziA;(j-)!7HcPDAB9`oY(e6rCDN-2fz5mCk8O3P6Vp9gkh-^X$U>@kXk-6PzcRBt(W zY=Xz;0eEb}C4E9Wgc$^gEHD|yV?_B^vUrUWpNVE_?+0|QEbqA&1?zF0-0H68m=D*2n!zC`am#bFpG^1U*xE()m2W z1nJ6`%HxB{qGzxC=%^+nyW-l)7-fj9ghHGSBD_FoDEIaCeGhf?yZJ=wc`R-8d5@oX)eCB*QP~ z(ofizZcNX)r2c@@c?KZKFo3#tUG1KNE0mQ}no$6ggx(a;xxVPMGAihks?w1y0JPoM z{$uN!7sP6$hgBd&*tdDsK@H=HE6EGJvT;4S} zrVkhJlN?$<)^5}ue`}oUXl7FI{`Yu=XzqzxPF66zfb9B;!1QzpF>zkmcenh0yYOuP z90p$I5p~n`u5Sd45<#jRL7v?)&)j)wZ08{B%2Ip%=!o7Q(t!QIaBt0y$ghwdq7R{v z9-{e#^bjFE#D3C4XfL6^VOLkY=re=V#wKeYgR}WJwQa@pZ~EXg!Xkq{rI4sNM^`Lx zmz-JH*2YPxn2&NwRDl)aIIH9tA5SmQ+?KwyXTZt^Xgt1wDxTF^yS8*{mY;VYPY=sz zPO)~DSSU6dmw{&hF6sKM^=6_$Rb3M>sB$zK@C{|x35Bt90f6pNr19ZTx`}~<*m-U7yoSEoH%Dh6>UXcdjU?>X5spt0VQI0Me%be+QKXkTpX5gvxBnvEXx zR6Iiq24j0F<<@Tk|+NKI*=9L3h&?_BT;a~I0^DeRbd;8d