diff --git a/Makefile b/Makefile index 52b7611ac..b2aa53b66 100644 --- a/Makefile +++ b/Makefile @@ -16,13 +16,13 @@ #all: test -.PHONY: ibm-block-csi-operator -ibm-block-csi-operator: +.PHONY: build +build: CGO_ENABLED=1 GOOS=linux go build -o build/_output/bin/ibm-block-csi-operator -gcflags all=-trimpath=${GOPATH} -asmflags all=-trimpath=${GOPATH} -mod=vendor cmd/manager/main.go .PHONY: test test: update - # for go 1.13+, set GOFLAGS to enable vendor mod + # for go 1.13+, set GOFLAGS to enable vendor mod for ginkgo GO111MODULE=on GOFLAGS='-mod=vendor' ginkgo -r -skipPackage pkg/controller .PHONY: update diff --git a/NOTICES b/NOTICES index 07da69947..a1c22b8e4 100644 --- a/NOTICES +++ b/NOTICES @@ -5,7 +5,7 @@ This file details additional third party software license agreements and third party notices and information that are required to be reproduced for the following programs: -Operator for IBM Block Storage CSI Driver version 1.0.0 +Operator for IBM Block Storage CSI Driver version 1.1.0 @@ -1040,7 +1040,7 @@ Version 7 =========================================================================== END OF TERMS AND CONDITIONS FOR SEPARATELY LICENSED CODE for Operator for -IBM Block Storage CSI Driver version 1.0.0 +IBM Block Storage CSI Driver version 1.1.0 =========================================================================== @@ -1051,7 +1051,7 @@ IBM Block Storage CSI Driver version 1.0.0 GNU GPL and / or LGPL Source Code for: -Operator for IBM Block Storage CSI Driver Version 1.0.0 Third Party +Operator for IBM Block Storage CSI Driver Version 1.1.0 Third Party Licenses and Notices =========================================================================== @@ -1063,24 +1063,24 @@ Licenses and Notices @@@@@@@@@@@@ =========================================================================== Lesser General Public License version 3.0: The product includes the -following licensed code to the licensee as Separately Licensed Code under -the GNU Lesser General Public License 3.0. +following licensed code to the licensee as Separately Licensed Code +under the GNU Lesser General Public License 3.0. =========================================================================== Prometheus version 1.8.2 -Source code to any of the above-listed packages distributed with Operator -for IBM Block Storage CSI Driver Version 1.0.0 Third Party Licenses and -Notices is available at the website below, when a URL is provided, or by -sending a request to the following address or email: +Source code to any of the above-listed packages distributed with +Operator for IBM Block Storage CSI Driver Version 1.1.0 Third Party +Licenses and Notices is available at the website below, when a URL is +provided, or by sending a request to the following address or email: IBM Corporation Attn: Dept 4XNA / 9032-2, Storage Open Source Management 9000 S. Rita Road Tucson, AZ 85744 -Please identify the name of the IBM product and the GPL or LGPL licensed -program(s) required in the request for source code. +Please identify the name of the IBM product and the GPL or LGPL +licensed program(s) required in the request for source code. =========================================================================== END of GNU LGPL Version 3.0 Notices and Information @@ -1117,6 +1117,7 @@ APACHE 2.0 LICENSED CODE: The Program includes all or portions of the following software which IBM obtained under the terms and conditions of the Apache License Version 2.0: +apiextensions-apiserver version 1.1.14 api-kubernetes version 1.14.1 apimacherniery-kubernetes version 1.14.1 cloud-provider-kubernetes version 1.14.1 @@ -1135,8 +1136,6 @@ prometheus version 1.8.2 spec version 0.17.2 thrift ---------------------------------------------------------------------------- - --------------------------------------------------------------------------- Start of Apache Software License Version 2.0 --------------------------------------------------------------------------- @@ -1348,8 +1347,103 @@ End of Apache Software License Version 2.0 --------------------------------------------------------------------------- + +=========================================================================== +NOTICE file corresponding to section 4(d) of the Apache License, +Version 2.0, in this case for the apiextensions-apiserver +version 1.1.14 distribution +=========================================================================== +CoreOS Project +Copyright 2014 CoreOS, Inc + +This product includes software developed at CoreOS, Inc. +(http://www.coreos.com/). + +--------------------------------------------------------------------------- +CoreOS Project +Copyright 2018 CoreOS, Inc + +This product includes software developed at CoreOS, Inc. + +--------------------------------------------------------------------------- + +CoreOS Project +Copyright 2014 CoreOS, Inc + +This product includes software developed at CoreOS, Inc. +(http://www.coreos.com/). + +--------------------------------------------------------------------------- + +Copyright 2012 Matt T. Proud (matt.proud@gmail.com) + +--------------------------------------------------------------------------- + +Prometheus instrumentation library for Go applications +Copyright 2012-2015 The Prometheus Authors + +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + + +The following components are included in this product: + +perks - a fork of https://github.com/bmizerany/perks +https://github.com/beorn7/perks +Copyright 2013-2015 Blake Mizerany, Björn Rabenstein +See https://github.com/beorn7/perks/blob/master/README.md for license details. + +Go support for Protocol Buffers - Google's data interchange format +http://github.com/golang/protobuf/ +Copyright 2010 The Go Authors +See source code for license details. + +Support for streaming Protocol Buffer messages for the Go language (golang). +https://github.com/matttproud/golang_protobuf_extensions +Copyright 2013 Matt T. Proud +Licensed under the Apache License, Version 2.0 + +--------------------------------------------------------------------------- + +Data model artifacts for Prometheus. +Copyright 2012-2015 The Prometheus Authors + +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + +--------------------------------------------------------------------------- + +Common libraries shared by Prometheus Go components. +Copyright 2015 The Prometheus Authors + +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + +--------------------------------------------------------------------------- + +procfs provides functions to retrieve system, kernel and process +metrics from the pseudo-filesystem proc. + +Copyright 2014-2015 The Prometheus Authors + +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + --------------------------------------------------------------------------- +Copyright 2011-2016 Canonical Ltd. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. =========================================================================== @@ -1549,175 +1643,1095 @@ Version 2.0, in this case for the prometheus version 1.8.2 distribution The Prometheus systems and service monitoring server Copyright 2012-2015 The Prometheus Authors -This product includes software developed at -SoundCloud Ltd. (http://soundcloud.com/). +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + + +The following components are included in this product: + +Bootstrap +http://getbootstrap.com +Copyright 2011-2014 Twitter, Inc. +Licensed under the MIT License + +bootstrap3-typeahead.js +https://github.com/bassjobsen/Bootstrap-3-Typeahead +Original written by @mdo and @fat +Copyright 2014 Bass Jobsen @bassjobsen +Licensed under the Apache License, Version 2.0 + +fuzzy +https://github.com/mattyork/fuzzy +Original written by @mattyork +Copyright 2012 Matt York +Licensed under the MIT License + +bootstrap-datetimepicker.js +https://github.com/Eonasdan/bootstrap-datetimepicker +Copyright 2015 Jonathan Peterson (@Eonasdan) +Licensed under the MIT License + +moment.js +https://github.com/moment/moment/ +Copyright JS Foundation and other contributors +Licensed under the MIT License + +Rickshaw +https://github.com/shutterstock/rickshaw +Copyright 2011-2014 by Shutterstock Images, LLC +See https://github.com/shutterstock/rickshaw/blob/master/LICENSE for +license details + +mustache.js +https://github.com/janl/mustache.js +Copyright 2009 Chris Wanstrath (Ruby) +Copyright 2010-2014 Jan Lehnardt (JavaScript) +Copyright 2010-2015 The mustache.js community +Licensed under the MIT License + +jQuery +https://jquery.org +Copyright jQuery Foundation and other contributors +Licensed under the MIT License + +Go support for Protocol Buffers - Google's data interchange format +http://github.com/golang/protobuf/ +Copyright 2010 The Go Authors +See source code for license details. + +Go support for leveled logs, analogous to +https://code.google.com/p/google-glog/ +Copyright 2013 Google Inc. +Licensed under the Apache License, Version 2.0 + +Support for streaming Protocol Buffer messages for the Go language (golang). +https://github.com/matttproud/golang_protobuf_extensions +Copyright 2013 Matt T. Proud +Licensed under the Apache License, Version 2.0 + +DNS library in Go +http://miek.nl/posts/2014/Aug/16/go-dns-package/ +Copyright 2009 The Go Authors, 2011 Miek Gieben +See https://github.com/miekg/dns/blob/master/LICENSE for +license details. + +LevelDB key/value database in Go +https://github.com/syndtr/goleveldb +Copyright 2012 Suryandaru Triandana +See https://github.com/syndtr/goleveldb/blob/master/LICENSE for +license details. + +gosnappy - a fork of code.google.com/p/snappy-go +https://github.com/syndtr/gosnappy +Copyright 2011 The Snappy-Go Authors +See https://github.com/syndtr/gosnappy/blob/master/LICENSE for +license details. + +go-zookeeper - Native ZooKeeper client for Go +https://github.com/samuel/go-zookeeper +Copyright (c) 2013, Samuel Stauffer +See https://github.com/samuel/go-zookeeper/blob/master/LICENSE for license +details. + +--------------------------------------------------------------------------- + +AWS SDK for Go +Copyright 2015 Amazon.com, Inc. or its affiliates. All Rights Reserved. +Copyright 2014-2015 Stripe, Inc. + +--------------------------------------------------------------------------- + +Copyright 2012 Matt T. Proud (matt.proud@gmail.com) + +--------------------------------------------------------------------------- + +Prometheus instrumentation library for Go applications +Copyright 2012-2015 The Prometheus Authors + +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + + +The following components are included in this product: + +perks - a fork of https://github.com/bmizerany/perks +https://github.com/beorn7/perks +Copyright 2013-2015 Blake Mizerany, Björn Rabenstein +See https://github.com/beorn7/perks/blob/master/README.md for license details. + +Go support for Protocol Buffers - Google's data interchange format +http://github.com/golang/protobuf/ +Copyright 2010 The Go Authors +See source code for license details. + +Support for streaming Protocol Buffer messages for the Go language (golang). +https://github.com/matttproud/golang_protobuf_extensions +Copyright 2013 Matt T. Proud +Licensed under the Apache License, Version 2.0 + +--------------------------------------------------------------------------- + +Data model artifacts for Prometheus. +Copyright 2012-2015 The Prometheus Authors + +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + +--------------------------------------------------------------------------- + +Common libraries shared by Prometheus Go components. +Copyright 2015 The Prometheus Authors + +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + +--------------------------------------------------------------------------- + +procfs provides functions to retrieve system, kernel and process +metrics from the pseudo-filesystem proc. + +Copyright 2014-2015 The Prometheus Authors + +This product includes software developed at +SoundCloud Ltd. (http://soundcloud.com/). + + +=========================================================================== +NOTICE file corresponding to section 4(d) of the Apache License, +Version 2.0, in this case for the thrift distribution +=========================================================================== +Apache Thrift +Copyright (C) 2006 - 2019, The Apache Software Foundation + +This product includes software developed at +The Apache Software Foundation (http://www.apache.org/). + +=========================================================================== +END OF APACHE 2.0 NOTICES AND INFORMATION +=========================================================================== + + + +@@@@@@@@@@@@ +=========================================================================== +apiextensions-apiserver version 1.1.14: The Program includes +apiextensions-apiserver version 1.1.14 software. IBM obtained +portions of the apiextensions-apiserver version 1.1.14 software under +the terms and conditions of the following license(s): +--------------------------------------------------------------------------- + +Copyright (c) 2009-2019 The Go Authors. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +* Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. +* Neither the name of Google Inc. nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +The MIT License (MIT) + +Copyright (c) 2014 Sam Ghods + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2012 Alex Ogier. All rights reserved. +Copyright (c) 2012 The Go Authors. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +* Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. +* Neither the name of Google Inc. nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2012 Péter Surányi. Portions Copyright (c) 2009 The Go +Authors. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +* Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. +* Neither the name of Google Inc. nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2016-2017 Uber Technologies, Inc. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2009 The oauth2 Authors. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +* Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. +* Neither the name of Google Inc. nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +The MIT License (MIT) + +Copyright (c) 2012-2015 Ugorji Nwoke. +All rights reserved. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (C) 2013 Blake Mizerany + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +"Software"), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND +NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE +LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION +OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION +WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +--------------------------------------------------------------------------- + +The MIT License (MIT) + +Copyright (c) 2013 Ben Johnson + +Permission is hereby granted, free of charge, to any person obtaining a +copy of this software and associated documentation files (the +"Software"), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be included +in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS +OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2009,2014 Google Inc. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +* Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. +* Neither the name of Google Inc. nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2013 Dario Castañé. All rights reserved. +Copyright (c) 2012 The Go Authors. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +* Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. +* Neither the name of Google Inc. nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2006 Kirill Simonov + +Permission is hereby granted, free of charge, to any person obtaining a copy of +this software and associated documentation files (the "Software"), to deal in +the Software without restriction, including without limitation the rights to +use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies +of the Software, and to permit persons to whom the Software is furnished to do +so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2010-2013 - Gustavo Niemeyer + +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: + +1. Redistributions of source code must retain the above copyright notice, this +list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright notice, +this list of conditions and the following disclaimer in the documentation +and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED +WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR +ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES +(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; +LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND +ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +ISC License + +Copyright (c) 2012-2016 Dave Collins + +Permission to use, copy, modify, and distribute this software for any +purpose with or without fee is hereby granted, provided that the above +copyright notice and this permission notice appear in all copies. + +THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES +WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF +MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR +ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES +WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN +ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF +OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright 2010 The Go Authors. All rights reserved. +https://github.com/golang/protobuf + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +* Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. +* Neither the name of Google Inc. nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2016 Mail.Ru Group + +Permission is hereby granted, free of charge, to any person obtaining a copy of +this software and associated documentation files (the "Software"), to deal in +the Software without restriction, including without limitation the rights to +use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of +the Software, and to permit persons to whom the Software is furnished to do so, +subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS +FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR +COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER +IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN +CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2014 Simon Eskildsen + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2015 Xiang Li + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2012 Dave Grijalva + +Permission is hereby granted, free of charge, to any person obtaining a +copy of this software and associated documentation files (the +"Software"), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be included +in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS +OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +--------------------------------------------------------------------------- +MIT License + +Copyright (c) 2016 json-iterator + +Permission is hereby granted, free of charge, to any person obtaining a +copy of this software and associated documentation files (the +"Software"), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be included +in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS +OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2012 - 2013 Mat Ryer and Tyler Bunnell + +Please consider promoting this project if you find it useful. + +Permission is hereby granted, free of charge, to any person +obtaining a copy of this software and associated documentation +files (the "Software"), to deal in the Software without restriction, +including without limitation the rights to use, copy, modify, merge, +publish, distribute, sublicense, and/or sell copies of the Software, +and to permit persons to whom the Software is furnished to do so, +subject to the following conditions: + +The above copyright notice and this permission notice shall be included +in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES +OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, +DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT +OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE +OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2013 The Gorilla WebSocket Authors. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: + +Redistributions of source code must retain the above copyright notice, this +list of conditions and the following disclaimer. + +Redistributions in binary form must reproduce the above copyright notice, +this list of conditions and the following disclaimer in the documentation +and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED +WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR +SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER +CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, +OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2012, Martin Angers +All rights reserved. + +Redistribution and use in source and binary forms, with or without modification, +are permitted provided that the following conditions are met: + +* Redistributions of source code must retain the above copyright notice, this +list of conditions and the following disclaimer. + +* Redistributions in binary form must reproduce the above copyright notice, this +list of conditions and the following disclaimer in the documentation and/or +other materials provided with the distribution. + +* Neither the name of the author nor the names of its contributors may be used +to endorse or promote products derived from this software without specific prior +written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED +WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR +ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES +(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; +LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON +ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2014, Evan Phoenix +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: + +* Redistributions of source code must retain the above copyright notice, this +list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above copyright notice +this list of conditions and the following disclaimer in the documentation +and/or other materials provided with the distribution. +* Neither the name of the Evan Phoenix nor the names of its contributors +may be used to endorse or promote products derived from this software +without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR +SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER +CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, +OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2013, Patrick Mezard +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + +Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +Redistributions in binary form must reproduce the above copyright +notice, this list of conditions and the following disclaimer in the +documentation and/or other materials provided with the distribution. +The names of its contributors may not be used to endorse or promote +products derived from this software without specific prior written +permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS +IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED +TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A +PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED +TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR +PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF +LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING +NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2012,2013 Ernest Micklei + +MIT License + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +"Software"), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND +NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE +LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION +OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION +WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +--------------------------------------------------------------------------- + +Copyright (c) 2010-2012 - Gustavo Niemeyer + +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: + +1. Redistributions of source code must retain the above copyright notice, this +list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright notice, +this list of conditions and the following disclaimer in the documentation +and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED +WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR +ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES +(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; +LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND +ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +--------------------------------------------------------------------------- + +Copyright (c) 2014 Nate Finch + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. + +--------------------------------------------------------------------------- +Copyright (c) 2014 Alex Saskevich -The following components are included in this product: +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: -Bootstrap -http://getbootstrap.com -Copyright 2011-2014 Twitter, Inc. -Licensed under the MIT License +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. -bootstrap3-typeahead.js -https://github.com/bassjobsen/Bootstrap-3-Typeahead -Original written by @mdo and @fat -Copyright 2014 Bass Jobsen @bassjobsen -Licensed under the Apache License, Version 2.0 +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. -fuzzy -https://github.com/mattyork/fuzzy -Original written by @mattyork -Copyright 2012 Matt York -Licensed under the MIT License +--------------------------------------------------------------------------- -bootstrap-datetimepicker.js -https://github.com/Eonasdan/bootstrap-datetimepicker -Copyright 2015 Jonathan Peterson (@Eonasdan) -Licensed under the MIT License +Copyright (c) 2013 Mitchell Hashimoto -moment.js -https://github.com/moment/moment/ -Copyright JS Foundation and other contributors -Licensed under the MIT License +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: -Rickshaw -https://github.com/shutterstock/rickshaw -Copyright 2011-2014 by Shutterstock Images, LLC -See https://github.com/shutterstock/rickshaw/blob/master/LICENSE for -license details +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. -mustache.js -https://github.com/janl/mustache.js -Copyright 2009 Chris Wanstrath (Ruby) -Copyright 2010-2014 Jan Lehnardt (JavaScript) -Copyright 2010-2015 The mustache.js community -Licensed under the MIT License +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. -jQuery -https://jquery.org -Copyright jQuery Foundation and other contributors -Licensed under the MIT License +--------------------------------------------------------------------------- -Go support for Protocol Buffers - Google's data interchange format -http://github.com/golang/protobuf/ -Copyright 2010 The Go Authors -See source code for license details. +Copyright (C) 2016 Travis Cline -Go support for leveled logs, analogous to -https://code.google.com/p/google-glog/ -Copyright 2013 Google Inc. -Licensed under the Apache License, Version 2.0 +Permission is hereby granted, free of charge, to any person obtaining a copy of +this software and associated documentation files (the "Software"), to deal in +the Software without restriction, including without limitation the rights to +use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of +the Software, and to permit persons to whom the Software is furnished to do so, +subject to the following conditions: -Support for streaming Protocol Buffer messages for the Go language (golang). -https://github.com/matttproud/golang_protobuf_extensions -Copyright 2013 Matt T. Proud -Licensed under the Apache License, Version 2.0 +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. -DNS library in Go -http://miek.nl/posts/2014/Aug/16/go-dns-package/ -Copyright 2009 The Go Authors, 2011 Miek Gieben -See https://github.com/miekg/dns/blob/master/LICENSE for -license details. +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS +FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR +COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER +IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN +CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. -LevelDB key/value database in Go -https://github.com/syndtr/goleveldb -Copyright 2012 Suryandaru Triandana -See https://github.com/syndtr/goleveldb/blob/master/LICENSE for -license details. +--------------------------------------------------------------------------- -gosnappy - a fork of code.google.com/p/snappy-go -https://github.com/syndtr/gosnappy -Copyright 2011 The Snappy-Go Authors -See https://github.com/syndtr/gosnappy/blob/master/LICENSE for -license details. +Copyright (c) 2015, Gengo, Inc. +All rights reserved. -go-zookeeper - Native ZooKeeper client for Go -https://github.com/samuel/go-zookeeper -Copyright (c) 2013, Samuel Stauffer -See https://github.com/samuel/go-zookeeper/blob/master/LICENSE for license -details. +Redistribution and use in source and binary forms, with or without modification, +are permitted provided that the following conditions are met: ---------------------------------------------------------------------------- +* Redistributions of source code must retain the above copyright notice, +this list of conditions and the following disclaimer. -AWS SDK for Go -Copyright 2015 Amazon.com, Inc. or its affiliates. All Rights Reserved. -Copyright 2014-2015 Stripe, Inc. +* Redistributions in binary form must reproduce the above copyright notice, +this list of conditions and the following disclaimer in the documentation +and/or other materials provided with the distribution. ---------------------------------------------------------------------------- +* Neither the name of Gengo, Inc. nor the names of its +contributors may be used to endorse or promote products derived from this +software without specific prior written permission. -Copyright 2012 Matt T. Proud (matt.proud@gmail.com) +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED +WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR +ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES +(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; +LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON +ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --------------------------------------------------------------------------- -Prometheus instrumentation library for Go applications -Copyright 2012-2015 The Prometheus Authors - -This product includes software developed at -SoundCloud Ltd. (http://soundcloud.com/). - +Copyright ©2013 The Gonum Authors. All rights reserved. -The following components are included in this product: +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: +* Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above copyright +notice, this list of conditions and the following disclaimer in the +documentation and/or other materials provided with the distribution. +* Neither the name of the gonum project nor the names of its authors and +contributors may be used to endorse or promote products derived from this +software without specific prior written permission. -perks - a fork of https://github.com/bmizerany/perks -https://github.com/beorn7/perks -Copyright 2013-2015 Blake Mizerany, Björn Rabenstein -See https://github.com/beorn7/perks/blob/master/README.md for license details. +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED +WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR +SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER +CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, +OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. -Go support for Protocol Buffers - Google's data interchange format -http://github.com/golang/protobuf/ -Copyright 2010 The Go Authors -See source code for license details. +--------------------------------------------------------------------------- -Support for streaming Protocol Buffer messages for the Go language (golang). -https://github.com/matttproud/golang_protobuf_extensions -Copyright 2013 Matt T. Proud -Licensed under the Apache License, Version 2.0 +Copyright (c) 2016, The GoGo Authors. All rights reserved. +Copyright (c) 2015, The GoGo Authors. All rights reserved. +Copyright (c) 2013, The GoGo Authors. All rights reserved. +http://github.com/gogo/protobuf ---------------------------------------------------------------------------- +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: -Data model artifacts for Prometheus. -Copyright 2012-2015 The Prometheus Authors + * Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. + * Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. -This product includes software developed at -SoundCloud Ltd. (http://soundcloud.com/). +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --------------------------------------------------------------------------- -Common libraries shared by Prometheus Go components. -Copyright 2015 The Prometheus Authors +Copyright (c) 2011, Open Knowledge Foundation Ltd. +All rights reserved. -This product includes software developed at -SoundCloud Ltd. (http://soundcloud.com/). +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: ---------------------------------------------------------------------------- + Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. -procfs provides functions to retrieve system, kernel and process -metrics from the pseudo-filesystem proc. + Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in + the documentation and/or other materials provided with the + distribution. -Copyright 2014-2015 The Prometheus Authors + Neither the name of the Open Knowledge Foundation Ltd. nor the + names of its contributors may be used to endorse or promote + products derived from this software without specific prior written + permission. -This product includes software developed at -SoundCloud Ltd. (http://soundcloud.com/). +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. -=========================================================================== -NOTICE file corresponding to section 4(d) of the Apache License, -Version 2.0, in this case for the thrift distribution -=========================================================================== -Apache Thrift -Copyright (C) 2006 - 2019, The Apache Software Foundation -This product includes software developed at -The Apache Software Foundation (http://www.apache.org/). - =========================================================================== -END OF APACHE 2.0 NOTICES AND INFORMATION +END OF apiextensions-apiserver version 1.1.14 NOTICES AND INFORMATION =========================================================================== - @@@@@@@@@@@@ =========================================================================== code-generator-kubernetes version 1.13.1: The Program includes @@ -3045,8 +4059,7 @@ SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. =========================================================================== -END OF prometheus-operator version 0.31.1 NOTICES AND -INFORMATION +END OF prometheus-operator version 0.31.1 NOTICES AND INFORMATION =========================================================================== @@ -3983,7 +4996,7 @@ END OF thrift NOTICES AND INFORMATION =========================================================================== END OF NOTICES AND INFORMATION FOR Operator for IBM Block -Storage CSI Driver Version 1.0.0 Third Party Licenses and +Storage CSI Driver Version 1.1.0 Third Party Licenses and Notices =========================================================================== diff --git a/README.md b/README.md index 8261b4935..63c3785f8 100644 --- a/README.md +++ b/README.md @@ -5,18 +5,22 @@ This is the official operator to deploy and manage IBM block storage CSI driver. Supported container platforms: - OpenShift v4.2 + - OpenShift v4.3 - Kubernetes v1.14 + - Kubernetes v1.16 Supported IBM storage systems: - IBM FlashSystem 9100 - - IBM Spectrum Virtualize - - IBM Storwize + - IBM Spectrum Virtualize Family (including IBM Flash family members built with IBM Spectrum Virtualize (FlashSystem 5010, 5030, 5100, 7200, 9100, 9200, 9200R) and IBM SAN Volume Controller (SVC) models SV2, SA2) - IBM FlashSystem A9000/R + - IBM DS8880 + - IBM DS8900 Supported operating systems: - RHEL 7.x (x86 architecture) + - RHCOS (x86 and IBM Z architecture) -Full documentation can be found on the [IBM knowledge center](https://www.ibm.com/support/knowledgecenter/SSRQ8T). +Full documentation can be found on the [IBM Knowledge Center](https://www.ibm.com/support/knowledgecenter/SSRQ8T).

@@ -28,8 +32,8 @@ Full documentation can be found on the [IBM knowledge center](https://www.ibm.co ### Preparing worker nodes Perform these steps for each worker node in Kubernetes cluster: -#### 1. Install Linux packages to ensure Fibre Channel and iSCSI connectivity -Skip this step if the packages are already installed. +#### 1. Perform this step to ensure iSCSI connectivity, when using RHEL OS. +If using RHCOS or if the packages are already installed, continue to the next step. RHEL 7.x: ```bash @@ -37,12 +41,87 @@ yum -y install iscsi-initiator-utils # Only if iSCSI connectivity is required yum -y install xfsprogs # Only if XFS file system is required ``` -#### 2. Configure Linux multipath devices on the host -Create and set the relevant storage system parameters in the `/etc/multipath.conf` file. -You can also use the default `multipath.conf` file, located in the `/usr/share/doc/device-mapper-multipath-*` directory. -Verify that the `systemctl status multipathd` output indicates that the multipath status is active and error-free. +#### 2. Configure Linux multipath devices on the host, using one of the following procedures. + +##### 2.1 Configuring for OpenShift Container Platform users (RHEL and RHCOS) + +The following yaml file example is for both Fibre Channel and iSCSI configurations. To support iSCSI, uncomment the last two lines in the file: + + +**Important:** The `99-ibm-attach.yaml` configuration file overrides any files that already exist on your system. Only use this file if the files mentioned in the yaml below are not already created. If one or more have been created, edit this yaml file, as necessary. + +Save the `99-ibm-attach.yaml` file. + +```bash +apiVersion: machineconfiguration.openshift.io/v1 +kind: MachineConfig +metadata: +labels: +machineconfiguration.openshift.io/role: worker +name: 99-ibm-attach +spec: +config: +ignition: +version: 2.2.0 +storage: +files: +- path: /etc/multipath.conf +mode: 384 +filesystem: root +contents: +source: data:,defaults%20%7B%0A%20%20%20%20path_checker%20tur%0A%20%20%20%20path_selector +%20%22round-robin%200%22%0A%20%20%20%20rr_weight%20uniform%0A%20%20%20%20prio%20const%0A +%20%20%20%20rr_min_io_rq%201%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20polling_interval +%2030%0A%20%20%20%20path_grouping_policy%20multibus%0A%20%20%20%20find_multipaths%20yes%0A +%20%20%20%20no_path_retry%20fail%0A%20%20%20%20user_friendly_names%20yes%0A%20%20%20%20failback +%20immediate%0A%20%20%20%20checker_timeout%2010%0A%20%20%20%20fast_io_fail_tmo%20off%0A%7D%0A%0Adevices +%20%7B%0A%20%20%20%20device%20%7B%0A%20%20%20%20%20%20%20%20path_checker%20tur%0A +%20%20%20%20%20%20%20%20product%20%22FlashSystem%22%0A%20%20%20%20%20%20%20%20vendor%20%22IBM%22%0A +%20%20%20%20%20%20%20%20rr_weight%20uniform%0A%20%20%20%20%20%20%20%20rr_min_io_rq +%204%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20path_grouping_policy +%20multibus%0A%20%20%20%20%20%20%20%20path_selector%20%22round-robin%200%22%0A +%20%20%20%20%20%20%20%20no_path_retry%20fail%0A%20%20%20%20%20%20%20%20failback%20immediate%0A +%20%20%20%20%7D%0A%20%20%20%20device%20%7B%0A%20%20%20%20%20%20%20%20path_checker%20tur%0A +%20%20%20%20%20%20%20%20product%20%22FlashSystem-9840%22%0A%20%20%20%20%20%20%20%20vendor%20%22IBM%22%0A +%20%20%20%20%20%20%20%20fast_io_fail_tmo%20off%0A%20%20%20%20%20%20%20%20rr_weight%20uniform%0A +%20%20%20%20%20%20%20%20rr_min_io_rq%201000%20%20%20%20%20%20%20%20%20%20%20%20%0A +%20%20%20%20%20%20%20%20path_grouping_policy%20multibus%0A%20%20%20%20%20%20%20%20path_selector +%20%22round-robin%200%22%0A%20%20%20%20%20%20%20%20no_path_retry%20fail%0A +%20%20%20%20%20%20%20%20failback%20immediate%0A%20%20%20%20%7D%0A%20%20%20%20device%20%7B%0A +%20%20%20%20%20%20%20%20vendor%20%22IBM%22%0A%20%20%20%20%20%20%20%20product%20%222145%22%0A +%20%20%20%20%20%20%20%20path_checker%20tur%0A%20%20%20%20%20%20%20%20features%20%221%20queue_if_no_path +%22%0A%20%20%20%20%20%20%20%20path_grouping_policy%20group_by_prio%0A +%20%20%20%20%20%20%20%20path_selector%20%22service-time%200%22%20%23%20Used%20by%20Red%20Hat%207.x%0A +%20%20%20%20%20%20%20%20prio%20alua%0A%20%20%20%20%20%20%20%20rr_min_io_rq%201%0A +%20%20%20%20%20%20%20%20rr_weight%20uniform%20%0A%20%20%20%20%20%20%20%20no_path_retry%20%225%22%0A +%20%20%20%20%20%20%20%20dev_loss_tmo%20120%0A%20%20%20%20%20%20%20%20failback%20immediate%0A%20%20%20%7D +%0A%7D%0A +verification: {} +- path: /etc/udev/rules.d/99-ibm-2145.rules +mode: 420 +filesystem: root +contents: +source: data:,%23%20Set%20SCSI%20command%20timeout%20to%20120s%20%28default%20%3D%3D +%2030%20or%2060%29%20for%20IBM%202145%20devices%0ASUBSYSTEM%3D%3D%22block%22%2C%20ACTION%3D%3D%22add +%22%2C%20ENV%7BID_VENDOR%7D%3D%3D%22IBM%22%2CENV%7BID_MODEL%7D%3D%3D%222145%22%2C%20RUN%2B%3D%22/bin/sh +%20-c%20%27echo%20120%20%3E/sys/block/%25k/device/timeout%27%22%0A +verification: {} +systemd: +units: +- name: multipathd.service +enabled: true +# Uncomment the following lines if this MachineConfig will be used with iSCSI connectivity +#- name: iscsid.service +# enabled: true +``` + +Apply the yaml file. +```bash +oc apply -f 99-ibm-attach.yaml +``` + +RHEL users should verify that the `systemctl status multipathd` output indicates that the multipath status is active and error-free. -RHEL 7.x: ```bash yum install device-mapper-multipath modprobe dm-multipath @@ -52,36 +131,24 @@ systemctl status multipathd multipath -ll ``` -**Important:** When configuring Linux multipath devices, verify that the `find_multipaths` parameter in the `multipath.conf` file is disabled. In RHEL 7.x, remove the`find_multipaths yes` string from the `multipath.conf` file. +##### 2.2 Configuring for Kubernetes users (RHEL) +Create and set the relevant storage system parameters in the `/etc/multipath.conf` file. You can also use the default `multipath.conf` file, located in the `/usr/share/doc/device-mapper-multipath-*` directory. -#### 3. Configure storage system connectivity -3.1. Define the hostname of each Kubernetes node on the relevant storage systems with the valid WWPN(for Fibre Channel) or IQN(for iSCSI) of the node. - -3.2. For Fibre Channel, configure the relevant zoning from the storage to the host. - -3.3. For iSCSI, perform the following steps: - -3.3.1. Make sure that the login to the iSCSI targets is permanent and remains available after a reboot of the worker node. To do this, verify that the node.startup in the /etc/iscsi/iscsid.conf file is set to automatic. If not, set it as required and then restart the iscsid service `$ service iscsid restart`. - -3.3.2. Discover and log into at least two iSCSI targets on the relevant storage systems. (NOTE: Without at least two ports, multipath device will not be created.) +Verify that the `systemctl status multipathd` output indicates that the multipath status is active and error-free. ```bash -$ iscsiadm -m discoverydb -t st -p ${STORAGE-SYSTEM-iSCSI-PORT-IP1}:3260 --discover -$ iscsiadm -m node -p ${STORAGE-SYSTEM-iSCSI-PORT-IP1} --login - -$ iscsiadm -m discoverydb -t st -p ${STORAGE-SYSTEM-iSCSI-PORT-IP2}:3260 --discover -$ iscsiadm -m node -p ${STORAGE-SYSTEM-iSCSI-PORT-IP2} --login +yum install device-mapper-multipath +modprobe dm-multipath +systemctl enable multipathd +systemctl start multipathd +systemctl status multipathd +multipath -ll ``` -3.3.3. Verify that the login was successful and display all targets that you logged into. The portal value must be the iSCSI target IP address. - -```bash -$ iscsiadm -m session --rescan -Rescanning session [sid: 1, target: {storage system IQN}, -portal: {STORAGE-SYSTEM-iSCSI-PORT-IP1},{port number} -portal: {STORAGE-SYSTEM-iSCSI-PORT-IP2},{port number} -``` +#### 3. Configure storage system connectivity +3.1. Define the hostname of each Kubernetes node on the relevant storage systems with the valid WWPN(for Fibre Channel) or IQN(for iSCSI) of the node. +3.2. For Fibre Channel, configure the relevant zoning from the storage to the host.
@@ -94,23 +161,31 @@ portal: {STORAGE-SYSTEM-iSCSI-PORT-IP2},{port number} ### Install the operator +#### 1. Download the manifest from GitHub. -1. Download the manifest from GitHub. ```bash curl https://raw.githubusercontent.com/IBM/ibm-block-csi-operator/master/deploy/installer/generated/ibm-block-csi-operator.yaml > ibm-block-csi-operator.yaml ``` -2. (Optional): If required, update the image fields in the ibm-block-csi-operator.yaml. -3. Install the operator. +#### 2. (Optional): If required, update the image fields in the ibm-block-csi-operator.yaml. + + +#### 3. Create a namespace. + +```bash +$ kubectl create ns +``` + +#### 4. Install the operator, while using a user-defined namespace. ```bash -$ kubectl apply -f ibm-block-csi-operator.yaml +$ kubectl -n apply -f ibm-block-csi-operator.yaml ``` ### Verify the operator is running: ```bash -$ kubectl get pod -l app.kubernetes.io/name=ibm-block-csi-operator -n kube-system +$ kubectl get pod -l app.kubernetes.io/name=ibm-block-csi-operator -n NAME READY STATUS RESTARTS AGE ibm-block-csi-operator-5bb7996b86-xntss 2/2 Running 0 10m ``` @@ -118,23 +193,23 @@ ibm-block-csi-operator-5bb7996b86-xntss 2/2 Running 0 10m ### Create an IBMBlockCSI custom resource -1. Download the manifest from GitHub. +#### 1. Download the manifest from GitHub. ```bash curl https://raw.githubusercontent.com/IBM/ibm-block-csi-operator/master/deploy/crds/csi.ibm.com_v1_ibmblockcsi_cr.yaml > csi.ibm.com_v1_ibmblockcsi_cr.yaml ``` -2. (Optional): If required, update the image fields in the csi.ibm.com_v1_ibmblockcsi_cr.yaml. +#### 2. (Optional): If required, update the image fields in the csi.ibm.com_v1_ibmblockcsi_cr.yaml. -3. Install the csi.ibm.com_v1_ibmblockcsi_cr.yaml. +#### 3. Install the csi.ibm.com_v1_ibmblockcsi_cr.yaml. ```bash -$ kubectl apply -f csi.ibm.com_v1_ibmblockcsi_cr.yaml +$ kubectl -n apply -f csi.ibm.com_v1_ibmblockcsi_cr.yaml ``` ### Verify the driver is running: ```bash -$ kubectl get all -n kube-system -l csi +$ kubectl get all -n -l csi NAME READY STATUS RESTARTS AGE pod/ibm-block-csi-controller-0 4/4 Running 0 9m36s pod/ibm-block-csi-node-jvmvh 3/3 Running 0 9m36s @@ -158,7 +233,7 @@ In order to use the driver, create the relevant storage classes and secrets, as This section describes how to: 1. Create a storage system secret - to define the storage system credentials (user and password) and its address. - 2. Configure the k8s storage class - to define the storage system pool name, secret reference, SpaceEfficiency (thin, compressed, or deduplicated) and fstype (xfs\ext4). + 2. Configure the storage class - to define the storage system pool name, secret reference, `SpaceEfficiency`, and `fstype`. #### 1. Create an array secret Create a secret file as follows `array-secret.yaml` and update the relevant credentials: @@ -167,14 +242,14 @@ Create a secret file as follows `array-secret.yaml` and update the relevant cred kind: Secret apiVersion: v1 metadata: - name: - namespace: kube-system + name: + namespace: type: Opaque stringData: - management_address: # Array management addresses - username: # Array username + management_address: # Array management addresses + username: # Array username data: - password: # Array password + password: # Array password ``` Apply the secret: @@ -183,9 +258,26 @@ Apply the secret: $ kubectl apply -f array-secret.yaml ``` +To create the secret using a command line terminal, use the following command: +```bash +kubectl create secret generic --from-literal=username= --fromliteral=password= --from-literal=management_address= -n +``` + #### 2. Create storage classes -Create a storage class `storageclass-gold.yaml` file as follows, with the relevant capabilities, pool and, array secret: +Create a storage class `storageclass-gold.yaml` file as follows, with the relevant capabilities, pool and, array secret. + +Use the `SpaceEfficiency` parameters for each storage system. These values are not case sensitive: +* IBM FlashSystem A9000 and A9000R + * Always includes deduplication and compression. + No need to specify during configuration. +* IBM Spectrum Virtualize Family + * `thin` + * `compressed` + * `deduplicated` +* IBM DS8000 Family + * `standard` (default value, if not specified) + * `thin` ``` kind: StorageClass @@ -194,8 +286,8 @@ metadata: name: gold provisioner: block.csi.ibm.com parameters: - #SpaceEfficiency: # Optional: Values applicable for Storwize are: thin, compressed, or deduplicated - pool: + #SpaceEfficiency: # Optional: Values applicable for Spectrum Virtualize Family are: thin, compressed, or deduplicated + pool: # DS8000 Family paramater is VALUE_POOL_ID csi.storage.k8s.io/provisioner-secret-name: csi.storage.k8s.io/provisioner-secret-namespace: @@ -203,9 +295,10 @@ parameters: csi.storage.k8s.io/controller-publish-secret-namespace: csi.storage.k8s.io/fstype: xfs # Optional: Values ext4/xfs. The default is ext4. + volume_name_prefix: # Optional: DS8000 Family maximum prefix length is 5 characters. Maximum prefix length for other systems is 20 characters. ``` -Apply the storage class: +#### 3. Apply the storage class: ```bash $ kubectl apply -f storageclass-gold.yaml @@ -228,6 +321,9 @@ storageclass.storage.k8s.io/gold created

+## Upgrading + +In order to upgrade the CSI operator and driver from a previous version, uninstall the existing driver and then install the newer version. ## Uninstalling @@ -247,7 +343,7 @@ $ kubectl delete -f ibm-block-csi-operator.yaml ## Licensing -Copyright 2019 IBM Corp. +Copyright 2020 IBM Corp. Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. diff --git a/build/Dockerfile.operator b/build/Dockerfile.operator index 3ba747bd2..3f462972c 100644 --- a/build/Dockerfile.operator +++ b/build/Dockerfile.operator @@ -27,11 +27,14 @@ RUN CGO_ENABLED=1 GOOS=linux go build \ FROM registry.access.redhat.com/ubi7/ubi-minimal:7.7-138 MAINTAINER IBM Storage +ARG VERSION=1.1.0 +ARG BUILD_NUMBER=0 + ###Required Labels LABEL name="Operator for IBM block storage CSI driver" \ vendor="IBM" \ - version="1.0.0" \ - release="b16" \ + version=$VERSION \ + release=$BUILD_NUMBER \ summary="The operator for IBM block storage CSI driver" \ description="The IBM block storage CSI driver enables container orchestrators, such as Kubernetes and OpenShift, to manage the life-cycle of persistent storage." \ io.k8s.display-name="Operator for IBM block storage CSI driver" \ diff --git a/build/bin/entrypoint b/build/bin/entrypoint index 3193408f8..457186bd8 100755 --- a/build/bin/entrypoint +++ b/build/bin/entrypoint @@ -1,12 +1,3 @@ #!/bin/sh -e -# This is documented here: -# https://docs.openshift.com/container-platform/3.11/creating_images/guidelines.html#openshift-specific-guidelines - -if ! whoami &>/dev/null; then - if [ -w /etc/passwd ]; then - echo "${USER_NAME:-ibm-block-csi-operator}:x:$(id -u):$(id -g):${USER_NAME:-ibm-block-csi-operator} user:${HOME}:/sbin/nologin" >> /etc/passwd - fi -fi - exec ${OPERATOR} $@ diff --git a/build/bin/user_setup b/build/bin/user_setup index 1e36064cb..fe1231363 100755 --- a/build/bin/user_setup +++ b/build/bin/user_setup @@ -2,12 +2,10 @@ set -x # ensure $HOME exists and is accessible by group 0 (we don't know what the runtime UID will be) +echo "${USER_NAME}:x:${USER_UID}:0:${USER_NAME} user:${HOME}:/sbin/nologin" >> /etc/passwd mkdir -p ${HOME} chown ${USER_UID}:0 ${HOME} chmod ug+rwx ${HOME} -# runtime user will need to be able to self-insert in /etc/passwd -chmod g+rw /etc/passwd - # no need for this script to remain in the image after running rm $0 diff --git a/build/ci/Dockerfile.unittest b/build/ci/Dockerfile.unittest index 2ba22ed64..f77f5f0f9 100644 --- a/build/ci/Dockerfile.unittest +++ b/build/ci/Dockerfile.unittest @@ -12,12 +12,22 @@ # See the License for the specific language governing permissions and # limitations under the License. -FROM golang:1.12.6 +FROM golang:1.13.1 WORKDIR /go/src/github.com/IBM/ibm-block-csi-operator -# ENV GO111MODULE=on +ENV GO111MODULE=on \ + GOROOT=/usr/local/go RUN go get github.com/onsi/ginkgo/ginkgo +RUN RELEASE_VERSION=v0.16.0 \ + && ARCH=$(uname -m) \ + && SDK_ASSET=operator-sdk-${RELEASE_VERSION}-${ARCH}-linux-gnu \ + && curl -LO https://github.com/operator-framework/operator-sdk/releases/download/${RELEASE_VERSION}/${SDK_ASSET} \ + && chmod +x ${SDK_ASSET} \ + && mkdir -p /usr/local/bin/ \ + && cp ${SDK_ASSET} /usr/local/bin/operator-sdk \ + && rm ${SDK_ASSET} + COPY . . CMD ["make", "test"] \ No newline at end of file diff --git a/build/ci/build_image.sh b/build/ci/build_push_image.sh similarity index 90% rename from build/ci/build_image.sh rename to build/ci/build_push_image.sh index e14b5cb03..9fe59b9f5 100755 --- a/build/ci/build_image.sh +++ b/build/ci/build_push_image.sh @@ -1,12 +1,11 @@ #!/bin/bash -xe # Validations -MANDATORY_ENVS="IMAGE_VERSION BUILD_NUMBER DOCKER_REGISTRY GIT_BRANCH" +MANDATORY_ENVS="IMAGE_VERSION BUILD_NUMBER DOCKER_REGISTRY OPERATOR_IMAGE GIT_BRANCH" for envi in $MANDATORY_ENVS; do [ -z "${!envi}" ] && { echo "Error - Env $envi is mandatory for the script."; exit 1; } || : done -OPERATOR_IMAGE=ibm-block-csi-operator NODE_IMAGE=ibm-node-agent # Prepare specific tag for the image @@ -25,7 +24,7 @@ operator_tag_latest=${operator_registry}:latest [ "$tag_latest" = "true" ] && taglatestflag="-t ${operator_tag_latest}" echo "Build and push the Operator image" -docker build -t ${operator_tag_specific} $taglatestflag -f build/Dockerfile.operator . +docker build -t ${operator_tag_specific} $taglatestflag -f build/Dockerfile.operator --build-arg VERSION="${IMAGE_VERSION}" --build-arg BUILD_NUMBER="${BUILD_NUMBER}" . docker push ${operator_tag_specific} [ "$tag_latest" = "true" ] && docker push ${operator_tag_latest} || : diff --git a/build/ci/jenkins_pipeline_build b/build/ci/jenkins_pipeline_build index 06bccdfdc..cac1bad38 100644 --- a/build/ci/jenkins_pipeline_build +++ b/build/ci/jenkins_pipeline_build @@ -11,7 +11,7 @@ pipeline { } stage ('Build and push images') { steps { - sh './build/ci/build_image.sh build/_output/reports/images_url' + sh './build/ci/build_push_image.sh build/_output/reports/images_url' } } } diff --git a/deploy/crds/csi.ibm.com_v1_ibmblockcsi_cr.yaml b/deploy/crds/csi.ibm.com_v1_ibmblockcsi_cr.yaml index 6d22984a6..38406a6e5 100644 --- a/deploy/crds/csi.ibm.com_v1_ibmblockcsi_cr.yaml +++ b/deploy/crds/csi.ibm.com_v1_ibmblockcsi_cr.yaml @@ -12,7 +12,7 @@ spec: # container and csi-provisioner, csi-attacher and livenessprobe sidecars. controller: repository: ibmcom/ibm-block-csi-driver-controller - tag: "1.0.0" + tag: "1.1.0" imagePullPolicy: IfNotPresent affinity: nodeAffinity: @@ -28,7 +28,7 @@ spec: # and csi-node-driver-registrar and livenessprobe sidecars. node: repository: ibmcom/ibm-block-csi-driver-node - tag: "1.0.0" + tag: "1.1.0" imagePullPolicy: IfNotPresent affinity: nodeAffinity: @@ -52,7 +52,7 @@ spec: imagePullPolicy: IfNotPresent - name: csi-provisioner repository: quay.io/k8scsi/csi-provisioner - tag: "v1.3.0" + tag: "v1.4.0" imagePullPolicy: IfNotPresent - name: csi-attacher repository: quay.io/k8scsi/csi-attacher diff --git a/deploy/installer/generated/ibm-block-csi-operator.yaml b/deploy/installer/generated/ibm-block-csi-operator.yaml index 641cea2c9..ed1c5606c 100644 --- a/deploy/installer/generated/ibm-block-csi-operator.yaml +++ b/deploy/installer/generated/ibm-block-csi-operator.yaml @@ -1,4 +1,4 @@ -# Code generated by update-copyright.sh. DO NOT EDIT. +# Code generated by update-installer.sh. DO NOT EDIT. apiVersion: apiextensions.k8s.io/v1beta1 kind: CustomResourceDefinition @@ -1425,7 +1425,7 @@ spec: annotations: productName: ibm-block-csi-operator productID: ibm-block-csi-operator - productVersion: "1.0.0" + productVersion: "1.1.0" spec: serviceAccountName: ibm-block-csi-operator affinity: @@ -1460,7 +1460,7 @@ spec: capabilities: drop: - ALL - image: ibmcom/ibm-block-csi-operator:1.0.0 + image: ibmcom/ibm-block-csi-operator:1.1.0 imagePullPolicy: IfNotPresent command: - ibm-block-csi-operator @@ -1529,6 +1529,7 @@ rules: - update - create - delete + - patch - apiGroups: - "" resources: @@ -1586,6 +1587,7 @@ rules: - list - watch - update + - patch - apiGroups: - storage.k8s.io resources: @@ -1627,6 +1629,15 @@ rules: - get - list - watch +- apiGroups: + - security.openshift.io + resourceNames: + - anyuid + - privileged + resources: + - securitycontextconstraints + verbs: + - use - apiGroups: - apiextensions.k8s.io resources: diff --git a/deploy/olm-catalog/ibm-block-csi-operator/1.0.0/ibm-block-csi-operator.v1.0.0.clusterserviceversion.yaml b/deploy/olm-catalog/ibm-block-csi-operator/1.0.0/ibm-block-csi-operator.v1.0.0.clusterserviceversion.yaml index 24492e5d5..588792569 100644 --- a/deploy/olm-catalog/ibm-block-csi-operator/1.0.0/ibm-block-csi-operator.v1.0.0.clusterserviceversion.yaml +++ b/deploy/olm-catalog/ibm-block-csi-operator/1.0.0/ibm-block-csi-operator.v1.0.0.clusterserviceversion.yaml @@ -8,7 +8,7 @@ metadata: categories: "Storage,Cloud Provider" certified: "true" containerImage: registry.connect.redhat.com/ibm/ibm-block-csi-operator:1.0.0 - createdAt: "2019-11-05T16:45:00Z" + createdAt: "2019-11-19T13:14:00Z" description: "Run IBM block storage CSI driver on OpenShift." repository: https://github.com/IBM/ibm-block-csi-operator support: IBM @@ -291,12 +291,6 @@ spec: - kind: ServiceAccount name: '' version: v1 - - kind: ClusterRole - name: '' - version: rbac.authorization.k8s.io/v1beta1 - - kind: ClusterRoleBinding - name: '' - version: rbac.authorization.k8s.io/v1beta1 - kind: StatefulSet name: '' version: apps/v1 @@ -488,6 +482,15 @@ spec: - get - list - watch + - apiGroups: + - security.openshift.io + resourceNames: + - anyuid + - privileged + resources: + - securitycontextconstraints + verbs: + - use - apiGroups: - apiextensions.k8s.io resources: diff --git a/deploy/olm-catalog/ibm-block-csi-operator/1.1.0/csi.ibm.com_ibmblockcsis_crd.yaml b/deploy/olm-catalog/ibm-block-csi-operator/1.1.0/csi.ibm.com_ibmblockcsis_crd.yaml new file mode 100644 index 000000000..91ee190f3 --- /dev/null +++ b/deploy/olm-catalog/ibm-block-csi-operator/1.1.0/csi.ibm.com_ibmblockcsis_crd.yaml @@ -0,0 +1,1396 @@ +apiVersion: apiextensions.k8s.io/v1beta1 +kind: CustomResourceDefinition +metadata: + name: ibmblockcsis.csi.ibm.com +spec: + group: csi.ibm.com + names: + kind: IBMBlockCSI + listKind: IBMBlockCSIList + plural: ibmblockcsis + shortNames: + - ibc + singular: ibmblockcsi + scope: Namespaced + subresources: + status: {} + validation: + openAPIV3Schema: + description: IBMBlockCSI is the Schema for the ibmblockcsis API + properties: + apiVersion: + description: 'APIVersion defines the versioned schema of this representation + of an object. Servers should convert recognized schemas to the latest + internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/api-conventions.md#resources' + type: string + kind: + description: 'Kind is a string value representing the REST resource this + object represents. Servers may infer this from the endpoint the client + submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/api-conventions.md#types-kinds' + type: string + metadata: + type: object + spec: + description: IBMBlockCSISpec defines the desired state of IBMBlockCSI + properties: + controller: + description: IBMBlockCSIControllerSpec defines the desired state of + IBMBlockCSIController + properties: + affinity: + description: Affinity is a group of affinity scheduling rules. + properties: + nodeAffinity: + description: Describes node affinity scheduling rules for the + pod. + properties: + preferredDuringSchedulingIgnoredDuringExecution: + description: The scheduler will prefer to schedule pods + to nodes that satisfy the affinity expressions specified + by this field, but it may choose a node that violates + one or more of the expressions. The node that is most + preferred is the one with the greatest sum of weights, + i.e. for each node that meets all of the scheduling requirements + (resource request, requiredDuringScheduling affinity expressions, + etc.), compute a sum by iterating through the elements + of this field and adding "weight" to the sum if the node + matches the corresponding matchExpressions; the node(s) + with the highest sum are the most preferred. + items: + description: An empty preferred scheduling term matches + all objects with implicit weight 0 (i.e. it's a no-op). + A null preferred scheduling term matches no objects + (i.e. is also a no-op). + properties: + preference: + description: A node selector term, associated with + the corresponding weight. + properties: + matchExpressions: + description: A list of node selector requirements + by node's labels. + items: + description: A node selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: The label key that the selector + applies to. + type: string + operator: + description: Represents a key's relationship + to a set of values. Valid operators are + In, NotIn, Exists, DoesNotExist. Gt, and + Lt. + type: string + values: + description: An array of string values. + If the operator is In or NotIn, the values + array must be non-empty. If the operator + is Exists or DoesNotExist, the values + array must be empty. If the operator is + Gt or Lt, the values array must have a + single element, which will be interpreted + as an integer. This array is replaced + during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchFields: + description: A list of node selector requirements + by node's fields. + items: + description: A node selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: The label key that the selector + applies to. + type: string + operator: + description: Represents a key's relationship + to a set of values. Valid operators are + In, NotIn, Exists, DoesNotExist. Gt, and + Lt. + type: string + values: + description: An array of string values. + If the operator is In or NotIn, the values + array must be non-empty. If the operator + is Exists or DoesNotExist, the values + array must be empty. If the operator is + Gt or Lt, the values array must have a + single element, which will be interpreted + as an integer. This array is replaced + during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + type: object + weight: + description: Weight associated with matching the corresponding + nodeSelectorTerm, in the range 1-100. + format: int32 + type: integer + required: + - preference + - weight + type: object + type: array + requiredDuringSchedulingIgnoredDuringExecution: + description: If the affinity requirements specified by this + field are not met at scheduling time, the pod will not + be scheduled onto the node. If the affinity requirements + specified by this field cease to be met at some point + during pod execution (e.g. due to an update), the system + may or may not try to eventually evict the pod from its + node. + properties: + nodeSelectorTerms: + description: Required. A list of node selector terms. + The terms are ORed. + items: + description: A null or empty node selector term matches + no objects. The requirements of them are ANDed. + The TopologySelectorTerm type implements a subset + of the NodeSelectorTerm. + properties: + matchExpressions: + description: A list of node selector requirements + by node's labels. + items: + description: A node selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: The label key that the selector + applies to. + type: string + operator: + description: Represents a key's relationship + to a set of values. Valid operators are + In, NotIn, Exists, DoesNotExist. Gt, and + Lt. + type: string + values: + description: An array of string values. + If the operator is In or NotIn, the values + array must be non-empty. If the operator + is Exists or DoesNotExist, the values + array must be empty. If the operator is + Gt or Lt, the values array must have a + single element, which will be interpreted + as an integer. This array is replaced + during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchFields: + description: A list of node selector requirements + by node's fields. + items: + description: A node selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: The label key that the selector + applies to. + type: string + operator: + description: Represents a key's relationship + to a set of values. Valid operators are + In, NotIn, Exists, DoesNotExist. Gt, and + Lt. + type: string + values: + description: An array of string values. + If the operator is In or NotIn, the values + array must be non-empty. If the operator + is Exists or DoesNotExist, the values + array must be empty. If the operator is + Gt or Lt, the values array must have a + single element, which will be interpreted + as an integer. This array is replaced + during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + type: object + type: array + required: + - nodeSelectorTerms + type: object + type: object + podAffinity: + description: Describes pod affinity scheduling rules (e.g. co-locate + this pod in the same node, zone, etc. as some other pod(s)). + properties: + preferredDuringSchedulingIgnoredDuringExecution: + description: The scheduler will prefer to schedule pods + to nodes that satisfy the affinity expressions specified + by this field, but it may choose a node that violates + one or more of the expressions. The node that is most + preferred is the one with the greatest sum of weights, + i.e. for each node that meets all of the scheduling requirements + (resource request, requiredDuringScheduling affinity expressions, + etc.), compute a sum by iterating through the elements + of this field and adding "weight" to the sum if the node + has pods which matches the corresponding podAffinityTerm; + the node(s) with the highest sum are the most preferred. + items: + description: The weights of all of the matched WeightedPodAffinityTerm + fields are added per-node to find the most preferred + node(s) + properties: + podAffinityTerm: + description: Required. A pod affinity term, associated + with the corresponding weight. + properties: + labelSelector: + description: A label query over a set of resources, + in this case pods. + properties: + matchExpressions: + description: matchExpressions is a list of + label selector requirements. The requirements + are ANDed. + items: + description: A label selector requirement + is a selector that contains values, a + key, and an operator that relates the + key and values. + properties: + key: + description: key is the label key that + the selector applies to. + type: string + operator: + description: operator represents a key's + relationship to a set of values. Valid + operators are In, NotIn, Exists and + DoesNotExist. + type: string + values: + description: values is an array of string + values. If the operator is In or NotIn, + the values array must be non-empty. + If the operator is Exists or DoesNotExist, + the values array must be empty. This + array is replaced during a strategic + merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchLabels: + additionalProperties: + type: string + description: matchLabels is a map of {key,value} + pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, + whose key field is "key", the operator is + "In", and the values array contains only + "value". The requirements are ANDed. + type: object + type: object + namespaces: + description: namespaces specifies which namespaces + the labelSelector applies to (matches against); + null or empty list means "this pod's namespace" + items: + type: string + type: array + topologyKey: + description: This pod should be co-located (affinity) + or not co-located (anti-affinity) with the pods + matching the labelSelector in the specified + namespaces, where co-located is defined as running + on a node whose value of the label with key + topologyKey matches that of any node on which + any of the selected pods is running. Empty topologyKey + is not allowed. + type: string + required: + - topologyKey + type: object + weight: + description: weight associated with matching the corresponding + podAffinityTerm, in the range 1-100. + format: int32 + type: integer + required: + - podAffinityTerm + - weight + type: object + type: array + requiredDuringSchedulingIgnoredDuringExecution: + description: If the affinity requirements specified by this + field are not met at scheduling time, the pod will not + be scheduled onto the node. If the affinity requirements + specified by this field cease to be met at some point + during pod execution (e.g. due to a pod label update), + the system may or may not try to eventually evict the + pod from its node. When there are multiple elements, the + lists of nodes corresponding to each podAffinityTerm are + intersected, i.e. all terms must be satisfied. + items: + description: Defines a set of pods (namely those matching + the labelSelector relative to the given namespace(s)) + that this pod should be co-located (affinity) or not + co-located (anti-affinity) with, where co-located is + defined as running on a node whose value of the label + with key matches that of any node on which + a pod of the set of pods is running + properties: + labelSelector: + description: A label query over a set of resources, + in this case pods. + properties: + matchExpressions: + description: matchExpressions is a list of label + selector requirements. The requirements are + ANDed. + items: + description: A label selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: key is the label key that the + selector applies to. + type: string + operator: + description: operator represents a key's + relationship to a set of values. Valid + operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: values is an array of string + values. If the operator is In or NotIn, + the values array must be non-empty. If + the operator is Exists or DoesNotExist, + the values array must be empty. This array + is replaced during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchLabels: + additionalProperties: + type: string + description: matchLabels is a map of {key,value} + pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, + whose key field is "key", the operator is "In", + and the values array contains only "value". + The requirements are ANDed. + type: object + type: object + namespaces: + description: namespaces specifies which namespaces + the labelSelector applies to (matches against); + null or empty list means "this pod's namespace" + items: + type: string + type: array + topologyKey: + description: This pod should be co-located (affinity) + or not co-located (anti-affinity) with the pods + matching the labelSelector in the specified namespaces, + where co-located is defined as running on a node + whose value of the label with key topologyKey matches + that of any node on which any of the selected pods + is running. Empty topologyKey is not allowed. + type: string + required: + - topologyKey + type: object + type: array + type: object + podAntiAffinity: + description: Describes pod anti-affinity scheduling rules (e.g. + avoid putting this pod in the same node, zone, etc. as some + other pod(s)). + properties: + preferredDuringSchedulingIgnoredDuringExecution: + description: The scheduler will prefer to schedule pods + to nodes that satisfy the anti-affinity expressions specified + by this field, but it may choose a node that violates + one or more of the expressions. The node that is most + preferred is the one with the greatest sum of weights, + i.e. for each node that meets all of the scheduling requirements + (resource request, requiredDuringScheduling anti-affinity + expressions, etc.), compute a sum by iterating through + the elements of this field and adding "weight" to the + sum if the node has pods which matches the corresponding + podAffinityTerm; the node(s) with the highest sum are + the most preferred. + items: + description: The weights of all of the matched WeightedPodAffinityTerm + fields are added per-node to find the most preferred + node(s) + properties: + podAffinityTerm: + description: Required. A pod affinity term, associated + with the corresponding weight. + properties: + labelSelector: + description: A label query over a set of resources, + in this case pods. + properties: + matchExpressions: + description: matchExpressions is a list of + label selector requirements. The requirements + are ANDed. + items: + description: A label selector requirement + is a selector that contains values, a + key, and an operator that relates the + key and values. + properties: + key: + description: key is the label key that + the selector applies to. + type: string + operator: + description: operator represents a key's + relationship to a set of values. Valid + operators are In, NotIn, Exists and + DoesNotExist. + type: string + values: + description: values is an array of string + values. If the operator is In or NotIn, + the values array must be non-empty. + If the operator is Exists or DoesNotExist, + the values array must be empty. This + array is replaced during a strategic + merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchLabels: + additionalProperties: + type: string + description: matchLabels is a map of {key,value} + pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, + whose key field is "key", the operator is + "In", and the values array contains only + "value". The requirements are ANDed. + type: object + type: object + namespaces: + description: namespaces specifies which namespaces + the labelSelector applies to (matches against); + null or empty list means "this pod's namespace" + items: + type: string + type: array + topologyKey: + description: This pod should be co-located (affinity) + or not co-located (anti-affinity) with the pods + matching the labelSelector in the specified + namespaces, where co-located is defined as running + on a node whose value of the label with key + topologyKey matches that of any node on which + any of the selected pods is running. Empty topologyKey + is not allowed. + type: string + required: + - topologyKey + type: object + weight: + description: weight associated with matching the corresponding + podAffinityTerm, in the range 1-100. + format: int32 + type: integer + required: + - podAffinityTerm + - weight + type: object + type: array + requiredDuringSchedulingIgnoredDuringExecution: + description: If the anti-affinity requirements specified + by this field are not met at scheduling time, the pod + will not be scheduled onto the node. If the anti-affinity + requirements specified by this field cease to be met at + some point during pod execution (e.g. due to a pod label + update), the system may or may not try to eventually evict + the pod from its node. When there are multiple elements, + the lists of nodes corresponding to each podAffinityTerm + are intersected, i.e. all terms must be satisfied. + items: + description: Defines a set of pods (namely those matching + the labelSelector relative to the given namespace(s)) + that this pod should be co-located (affinity) or not + co-located (anti-affinity) with, where co-located is + defined as running on a node whose value of the label + with key matches that of any node on which + a pod of the set of pods is running + properties: + labelSelector: + description: A label query over a set of resources, + in this case pods. + properties: + matchExpressions: + description: matchExpressions is a list of label + selector requirements. The requirements are + ANDed. + items: + description: A label selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: key is the label key that the + selector applies to. + type: string + operator: + description: operator represents a key's + relationship to a set of values. Valid + operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: values is an array of string + values. If the operator is In or NotIn, + the values array must be non-empty. If + the operator is Exists or DoesNotExist, + the values array must be empty. This array + is replaced during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchLabels: + additionalProperties: + type: string + description: matchLabels is a map of {key,value} + pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, + whose key field is "key", the operator is "In", + and the values array contains only "value". + The requirements are ANDed. + type: object + type: object + namespaces: + description: namespaces specifies which namespaces + the labelSelector applies to (matches against); + null or empty list means "this pod's namespace" + items: + type: string + type: array + topologyKey: + description: This pod should be co-located (affinity) + or not co-located (anti-affinity) with the pods + matching the labelSelector in the specified namespaces, + where co-located is defined as running on a node + whose value of the label with key topologyKey matches + that of any node on which any of the selected pods + is running. Empty topologyKey is not allowed. + type: string + required: + - topologyKey + type: object + type: array + type: object + type: object + imagePullPolicy: + description: PullPolicy describes a policy for if/when to pull a + container image + type: string + repository: + type: string + tag: + type: string + tolerations: + items: + description: The pod this Toleration is attached to tolerates + any taint that matches the triple using the + matching operator . + properties: + effect: + description: Effect indicates the taint effect to match. Empty + means match all taint effects. When specified, allowed values + are NoSchedule, PreferNoSchedule and NoExecute. + type: string + key: + description: Key is the taint key that the toleration applies + to. Empty means match all taint keys. If the key is empty, + operator must be Exists; this combination means to match + all values and all keys. + type: string + operator: + description: Operator represents a key's relationship to the + value. Valid operators are Exists and Equal. Defaults to + Equal. Exists is equivalent to wildcard for value, so that + a pod can tolerate all taints of a particular category. + type: string + tolerationSeconds: + description: TolerationSeconds represents the period of time + the toleration (which must be of effect NoExecute, otherwise + this field is ignored) tolerates the taint. By default, + it is not set, which means tolerate the taint forever (do + not evict). Zero and negative values will be treated as + 0 (evict immediately) by the system. + format: int64 + type: integer + value: + description: Value is the taint value the toleration matches + to. If the operator is Exists, the value should be empty, + otherwise just a regular string. + type: string + type: object + type: array + required: + - repository + - tag + type: object + imagePullSecrets: + items: + type: string + type: array + node: + description: IBMBlockCSINodeSpec defines the desired state of IBMBlockCSINode + properties: + affinity: + description: Affinity is a group of affinity scheduling rules. + properties: + nodeAffinity: + description: Describes node affinity scheduling rules for the + pod. + properties: + preferredDuringSchedulingIgnoredDuringExecution: + description: The scheduler will prefer to schedule pods + to nodes that satisfy the affinity expressions specified + by this field, but it may choose a node that violates + one or more of the expressions. The node that is most + preferred is the one with the greatest sum of weights, + i.e. for each node that meets all of the scheduling requirements + (resource request, requiredDuringScheduling affinity expressions, + etc.), compute a sum by iterating through the elements + of this field and adding "weight" to the sum if the node + matches the corresponding matchExpressions; the node(s) + with the highest sum are the most preferred. + items: + description: An empty preferred scheduling term matches + all objects with implicit weight 0 (i.e. it's a no-op). + A null preferred scheduling term matches no objects + (i.e. is also a no-op). + properties: + preference: + description: A node selector term, associated with + the corresponding weight. + properties: + matchExpressions: + description: A list of node selector requirements + by node's labels. + items: + description: A node selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: The label key that the selector + applies to. + type: string + operator: + description: Represents a key's relationship + to a set of values. Valid operators are + In, NotIn, Exists, DoesNotExist. Gt, and + Lt. + type: string + values: + description: An array of string values. + If the operator is In or NotIn, the values + array must be non-empty. If the operator + is Exists or DoesNotExist, the values + array must be empty. If the operator is + Gt or Lt, the values array must have a + single element, which will be interpreted + as an integer. This array is replaced + during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchFields: + description: A list of node selector requirements + by node's fields. + items: + description: A node selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: The label key that the selector + applies to. + type: string + operator: + description: Represents a key's relationship + to a set of values. Valid operators are + In, NotIn, Exists, DoesNotExist. Gt, and + Lt. + type: string + values: + description: An array of string values. + If the operator is In or NotIn, the values + array must be non-empty. If the operator + is Exists or DoesNotExist, the values + array must be empty. If the operator is + Gt or Lt, the values array must have a + single element, which will be interpreted + as an integer. This array is replaced + during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + type: object + weight: + description: Weight associated with matching the corresponding + nodeSelectorTerm, in the range 1-100. + format: int32 + type: integer + required: + - preference + - weight + type: object + type: array + requiredDuringSchedulingIgnoredDuringExecution: + description: If the affinity requirements specified by this + field are not met at scheduling time, the pod will not + be scheduled onto the node. If the affinity requirements + specified by this field cease to be met at some point + during pod execution (e.g. due to an update), the system + may or may not try to eventually evict the pod from its + node. + properties: + nodeSelectorTerms: + description: Required. A list of node selector terms. + The terms are ORed. + items: + description: A null or empty node selector term matches + no objects. The requirements of them are ANDed. + The TopologySelectorTerm type implements a subset + of the NodeSelectorTerm. + properties: + matchExpressions: + description: A list of node selector requirements + by node's labels. + items: + description: A node selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: The label key that the selector + applies to. + type: string + operator: + description: Represents a key's relationship + to a set of values. Valid operators are + In, NotIn, Exists, DoesNotExist. Gt, and + Lt. + type: string + values: + description: An array of string values. + If the operator is In or NotIn, the values + array must be non-empty. If the operator + is Exists or DoesNotExist, the values + array must be empty. If the operator is + Gt or Lt, the values array must have a + single element, which will be interpreted + as an integer. This array is replaced + during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchFields: + description: A list of node selector requirements + by node's fields. + items: + description: A node selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: The label key that the selector + applies to. + type: string + operator: + description: Represents a key's relationship + to a set of values. Valid operators are + In, NotIn, Exists, DoesNotExist. Gt, and + Lt. + type: string + values: + description: An array of string values. + If the operator is In or NotIn, the values + array must be non-empty. If the operator + is Exists or DoesNotExist, the values + array must be empty. If the operator is + Gt or Lt, the values array must have a + single element, which will be interpreted + as an integer. This array is replaced + during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + type: object + type: array + required: + - nodeSelectorTerms + type: object + type: object + podAffinity: + description: Describes pod affinity scheduling rules (e.g. co-locate + this pod in the same node, zone, etc. as some other pod(s)). + properties: + preferredDuringSchedulingIgnoredDuringExecution: + description: The scheduler will prefer to schedule pods + to nodes that satisfy the affinity expressions specified + by this field, but it may choose a node that violates + one or more of the expressions. The node that is most + preferred is the one with the greatest sum of weights, + i.e. for each node that meets all of the scheduling requirements + (resource request, requiredDuringScheduling affinity expressions, + etc.), compute a sum by iterating through the elements + of this field and adding "weight" to the sum if the node + has pods which matches the corresponding podAffinityTerm; + the node(s) with the highest sum are the most preferred. + items: + description: The weights of all of the matched WeightedPodAffinityTerm + fields are added per-node to find the most preferred + node(s) + properties: + podAffinityTerm: + description: Required. A pod affinity term, associated + with the corresponding weight. + properties: + labelSelector: + description: A label query over a set of resources, + in this case pods. + properties: + matchExpressions: + description: matchExpressions is a list of + label selector requirements. The requirements + are ANDed. + items: + description: A label selector requirement + is a selector that contains values, a + key, and an operator that relates the + key and values. + properties: + key: + description: key is the label key that + the selector applies to. + type: string + operator: + description: operator represents a key's + relationship to a set of values. Valid + operators are In, NotIn, Exists and + DoesNotExist. + type: string + values: + description: values is an array of string + values. If the operator is In or NotIn, + the values array must be non-empty. + If the operator is Exists or DoesNotExist, + the values array must be empty. This + array is replaced during a strategic + merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchLabels: + additionalProperties: + type: string + description: matchLabels is a map of {key,value} + pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, + whose key field is "key", the operator is + "In", and the values array contains only + "value". The requirements are ANDed. + type: object + type: object + namespaces: + description: namespaces specifies which namespaces + the labelSelector applies to (matches against); + null or empty list means "this pod's namespace" + items: + type: string + type: array + topologyKey: + description: This pod should be co-located (affinity) + or not co-located (anti-affinity) with the pods + matching the labelSelector in the specified + namespaces, where co-located is defined as running + on a node whose value of the label with key + topologyKey matches that of any node on which + any of the selected pods is running. Empty topologyKey + is not allowed. + type: string + required: + - topologyKey + type: object + weight: + description: weight associated with matching the corresponding + podAffinityTerm, in the range 1-100. + format: int32 + type: integer + required: + - podAffinityTerm + - weight + type: object + type: array + requiredDuringSchedulingIgnoredDuringExecution: + description: If the affinity requirements specified by this + field are not met at scheduling time, the pod will not + be scheduled onto the node. If the affinity requirements + specified by this field cease to be met at some point + during pod execution (e.g. due to a pod label update), + the system may or may not try to eventually evict the + pod from its node. When there are multiple elements, the + lists of nodes corresponding to each podAffinityTerm are + intersected, i.e. all terms must be satisfied. + items: + description: Defines a set of pods (namely those matching + the labelSelector relative to the given namespace(s)) + that this pod should be co-located (affinity) or not + co-located (anti-affinity) with, where co-located is + defined as running on a node whose value of the label + with key matches that of any node on which + a pod of the set of pods is running + properties: + labelSelector: + description: A label query over a set of resources, + in this case pods. + properties: + matchExpressions: + description: matchExpressions is a list of label + selector requirements. The requirements are + ANDed. + items: + description: A label selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: key is the label key that the + selector applies to. + type: string + operator: + description: operator represents a key's + relationship to a set of values. Valid + operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: values is an array of string + values. If the operator is In or NotIn, + the values array must be non-empty. If + the operator is Exists or DoesNotExist, + the values array must be empty. This array + is replaced during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchLabels: + additionalProperties: + type: string + description: matchLabels is a map of {key,value} + pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, + whose key field is "key", the operator is "In", + and the values array contains only "value". + The requirements are ANDed. + type: object + type: object + namespaces: + description: namespaces specifies which namespaces + the labelSelector applies to (matches against); + null or empty list means "this pod's namespace" + items: + type: string + type: array + topologyKey: + description: This pod should be co-located (affinity) + or not co-located (anti-affinity) with the pods + matching the labelSelector in the specified namespaces, + where co-located is defined as running on a node + whose value of the label with key topologyKey matches + that of any node on which any of the selected pods + is running. Empty topologyKey is not allowed. + type: string + required: + - topologyKey + type: object + type: array + type: object + podAntiAffinity: + description: Describes pod anti-affinity scheduling rules (e.g. + avoid putting this pod in the same node, zone, etc. as some + other pod(s)). + properties: + preferredDuringSchedulingIgnoredDuringExecution: + description: The scheduler will prefer to schedule pods + to nodes that satisfy the anti-affinity expressions specified + by this field, but it may choose a node that violates + one or more of the expressions. The node that is most + preferred is the one with the greatest sum of weights, + i.e. for each node that meets all of the scheduling requirements + (resource request, requiredDuringScheduling anti-affinity + expressions, etc.), compute a sum by iterating through + the elements of this field and adding "weight" to the + sum if the node has pods which matches the corresponding + podAffinityTerm; the node(s) with the highest sum are + the most preferred. + items: + description: The weights of all of the matched WeightedPodAffinityTerm + fields are added per-node to find the most preferred + node(s) + properties: + podAffinityTerm: + description: Required. A pod affinity term, associated + with the corresponding weight. + properties: + labelSelector: + description: A label query over a set of resources, + in this case pods. + properties: + matchExpressions: + description: matchExpressions is a list of + label selector requirements. The requirements + are ANDed. + items: + description: A label selector requirement + is a selector that contains values, a + key, and an operator that relates the + key and values. + properties: + key: + description: key is the label key that + the selector applies to. + type: string + operator: + description: operator represents a key's + relationship to a set of values. Valid + operators are In, NotIn, Exists and + DoesNotExist. + type: string + values: + description: values is an array of string + values. If the operator is In or NotIn, + the values array must be non-empty. + If the operator is Exists or DoesNotExist, + the values array must be empty. This + array is replaced during a strategic + merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchLabels: + additionalProperties: + type: string + description: matchLabels is a map of {key,value} + pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, + whose key field is "key", the operator is + "In", and the values array contains only + "value". The requirements are ANDed. + type: object + type: object + namespaces: + description: namespaces specifies which namespaces + the labelSelector applies to (matches against); + null or empty list means "this pod's namespace" + items: + type: string + type: array + topologyKey: + description: This pod should be co-located (affinity) + or not co-located (anti-affinity) with the pods + matching the labelSelector in the specified + namespaces, where co-located is defined as running + on a node whose value of the label with key + topologyKey matches that of any node on which + any of the selected pods is running. Empty topologyKey + is not allowed. + type: string + required: + - topologyKey + type: object + weight: + description: weight associated with matching the corresponding + podAffinityTerm, in the range 1-100. + format: int32 + type: integer + required: + - podAffinityTerm + - weight + type: object + type: array + requiredDuringSchedulingIgnoredDuringExecution: + description: If the anti-affinity requirements specified + by this field are not met at scheduling time, the pod + will not be scheduled onto the node. If the anti-affinity + requirements specified by this field cease to be met at + some point during pod execution (e.g. due to a pod label + update), the system may or may not try to eventually evict + the pod from its node. When there are multiple elements, + the lists of nodes corresponding to each podAffinityTerm + are intersected, i.e. all terms must be satisfied. + items: + description: Defines a set of pods (namely those matching + the labelSelector relative to the given namespace(s)) + that this pod should be co-located (affinity) or not + co-located (anti-affinity) with, where co-located is + defined as running on a node whose value of the label + with key matches that of any node on which + a pod of the set of pods is running + properties: + labelSelector: + description: A label query over a set of resources, + in this case pods. + properties: + matchExpressions: + description: matchExpressions is a list of label + selector requirements. The requirements are + ANDed. + items: + description: A label selector requirement is + a selector that contains values, a key, and + an operator that relates the key and values. + properties: + key: + description: key is the label key that the + selector applies to. + type: string + operator: + description: operator represents a key's + relationship to a set of values. Valid + operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: values is an array of string + values. If the operator is In or NotIn, + the values array must be non-empty. If + the operator is Exists or DoesNotExist, + the values array must be empty. This array + is replaced during a strategic merge patch. + items: + type: string + type: array + required: + - key + - operator + type: object + type: array + matchLabels: + additionalProperties: + type: string + description: matchLabels is a map of {key,value} + pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, + whose key field is "key", the operator is "In", + and the values array contains only "value". + The requirements are ANDed. + type: object + type: object + namespaces: + description: namespaces specifies which namespaces + the labelSelector applies to (matches against); + null or empty list means "this pod's namespace" + items: + type: string + type: array + topologyKey: + description: This pod should be co-located (affinity) + or not co-located (anti-affinity) with the pods + matching the labelSelector in the specified namespaces, + where co-located is defined as running on a node + whose value of the label with key topologyKey matches + that of any node on which any of the selected pods + is running. Empty topologyKey is not allowed. + type: string + required: + - topologyKey + type: object + type: array + type: object + type: object + imagePullPolicy: + description: PullPolicy describes a policy for if/when to pull a + container image + type: string + repository: + type: string + tag: + type: string + tolerations: + items: + description: The pod this Toleration is attached to tolerates + any taint that matches the triple using the + matching operator . + properties: + effect: + description: Effect indicates the taint effect to match. Empty + means match all taint effects. When specified, allowed values + are NoSchedule, PreferNoSchedule and NoExecute. + type: string + key: + description: Key is the taint key that the toleration applies + to. Empty means match all taint keys. If the key is empty, + operator must be Exists; this combination means to match + all values and all keys. + type: string + operator: + description: Operator represents a key's relationship to the + value. Valid operators are Exists and Equal. Defaults to + Equal. Exists is equivalent to wildcard for value, so that + a pod can tolerate all taints of a particular category. + type: string + tolerationSeconds: + description: TolerationSeconds represents the period of time + the toleration (which must be of effect NoExecute, otherwise + this field is ignored) tolerates the taint. By default, + it is not set, which means tolerate the taint forever (do + not evict). Zero and negative values will be treated as + 0 (evict immediately) by the system. + format: int64 + type: integer + value: + description: Value is the taint value the toleration matches + to. If the operator is Exists, the value should be empty, + otherwise just a regular string. + type: string + type: object + type: array + required: + - repository + - tag + type: object + sidecars: + items: + properties: + imagePullPolicy: + description: The pullPolicy of the csi sidecar image + type: string + name: + description: The name of the csi sidecar image + type: string + repository: + description: The repository of the csi sidecar image + type: string + tag: + description: The tag of the csi sidecar image + type: string + required: + - name + - repository + - tag + type: object + type: array + required: + - controller + - node + type: object + status: + description: IBMBlockCSIStatus defines the observed state of IBMBlockCSI + properties: + controllerReady: + type: boolean + nodeReady: + type: boolean + phase: + description: Phase is the driver running phase + type: string + version: + description: Version is the current driver version + type: string + required: + - controllerReady + - nodeReady + - phase + - version + type: object + type: object + version: v1 + versions: + - name: v1 + served: true + storage: true diff --git a/deploy/olm-catalog/ibm-block-csi-operator/1.1.0/ibm-block-csi-operator.v1.1.0.clusterserviceversion.yaml b/deploy/olm-catalog/ibm-block-csi-operator/1.1.0/ibm-block-csi-operator.v1.1.0.clusterserviceversion.yaml new file mode 100644 index 000000000..0e6ec6042 --- /dev/null +++ b/deploy/olm-catalog/ibm-block-csi-operator/1.1.0/ibm-block-csi-operator.v1.1.0.clusterserviceversion.yaml @@ -0,0 +1,630 @@ +apiVersion: operators.coreos.com/v1alpha1 +kind: ClusterServiceVersion +metadata: + name: ibm-block-csi-operator.v1.1.0 + namespace: placeholder + annotations: + capabilities: "Basic Install" + categories: "Storage,Cloud Provider" + certified: "true" + containerImage: registry.connect.redhat.com/ibm/ibm-block-csi-operator:1.1.0 + createdAt: "2020-02-19T13:14:00Z" + description: "Run IBM block storage CSI driver on OpenShift." + repository: https://github.com/IBM/ibm-block-csi-operator + support: IBM + alm-examples: >- + [ + { + "apiVersion": "csi.ibm.com/v1", + "kind": "IBMBlockCSI", + "metadata": { + "name": "ibm-block-csi" + }, + "spec": { + "controller": { + "repository": "ibmcom/ibm-block-csi-driver-controller", + "tag": "1.1.0", + "imagePullPolicy": "IfNotPresent", + "affinity": { + "nodeAffinity": { + "requiredDuringSchedulingIgnoredDuringExecution": { + "nodeSelectorTerms": [ + { + "matchExpressions": [ + { + "key": "kubernetes.io/arch", + "operator": "In", + "values": [ + "amd64" + ] + } + ] + } + ] + } + } + } + }, + "node": { + "repository": "ibmcom/ibm-block-csi-driver-node", + "tag": "1.1.0", + "imagePullPolicy": "IfNotPresent", + "affinity": { + "nodeAffinity": { + "requiredDuringSchedulingIgnoredDuringExecution": { + "nodeSelectorTerms": [ + { + "matchExpressions": [ + { + "key": "kubernetes.io/arch", + "operator": "In", + "values": [ + "amd64" + ] + } + ] + } + ] + } + } + } + }, + "sidecars": [ + { + "name": "csi-node-driver-registrar", + "repository": "quay.io/k8scsi/csi-node-driver-registrar", + "tag": "v1.2.0", + "imagePullPolicy": "IfNotPresent" + }, + { + "name": "csi-provisioner", + "repository": "quay.io/k8scsi/csi-provisioner", + "tag": "v1.3.0", + "imagePullPolicy": "IfNotPresent" + }, + { + "name": "csi-attacher", + "repository": "quay.io/k8scsi/csi-attacher", + "tag": "v1.2.1", + "imagePullPolicy": "IfNotPresent" + }, + { + "name": "livenessprobe", + "repository": "quay.io/k8scsi/livenessprobe", + "tag": "v1.1.0", + "imagePullPolicy": "IfNotPresent" + } + ] + } + } + ] +spec: + displayName: "Operator for IBM block storage CSI driver" + description: | + **IBM block storage CSI driver** is a Container Storage Interface (CSI) Driver for IBM block storage systems which enables container orchestrators to manage the life cycle of persistent storage. + + This is the official operator to deploy and manage IBM block storage CSI driver. + + Supported container platforms: + - OpenShift v4.2 + - OpenShift v4.3 + - Kubernetes v1.14 + - Kubernetes v1.16 + + Supported IBM storage systems: + - IBM FlashSystem 9100 + - IBM Spectrum Virtualize Family (including IBM Flash family members built with IBM Spectrum Virtualize (FlashSystem 5010, 5030, 5100, 7200, 9100, 9200, 9200R) and IBM SAN Volume Controller (SVC) models SV2, SA2) + - IBM FlashSystem A9000/R + - IBM DS8880 + - IBM DS8900 + + Supported operating systems: + - RHEL 7.x (x86 architecture) + - RHCOS (x86 and IBM Z architecture) + + Full documentation can be found on the [IBM Knowledge Center](https://www.ibm.com/support/knowledgecenter/SSRQ8T). + + ## Prerequisites + + ### Preparing worker nodes + Perform these steps for each worker node: + + #### 1. Perform this step to ensure iSCSI connectivity, when using RHEL OS. + If using RHCOS or if the packages are already installed, continue to the next step. + + RHEL 7.x: + ```bash + yum -y install iscsi-initiator-utils # Only if iSCSI connectivity is required + yum -y install xfsprogs # Only if XFS file system is required + ``` + + #### 2. Configure Linux multipath devices on the host, using one of the following procedures. + The following yaml file example is for both Fibre Channel and iSCSI configurations. To support iSCSI, uncomment the last two lines in the file: + + **Important:** The `99-ibm-attach.yaml` configuration file overrides any files that already exist on your system. Only use this file if the files mentioned in the yaml below are not already created. If one or more have been created, edit this yaml file, as necessary. + + Save the `99-ibm-attach.yaml` file. + + ```bash + apiVersion: machineconfiguration.openshift.io/v1 + kind: MachineConfig + metadata: + labels: + machineconfiguration.openshift.io/role: worker + name: 99-ibm-attach + spec: + config: + ignition: + version: 2.2.0 + storage: + files: + - path: /etc/multipath.conf + mode: 384 + filesystem: root + contents: + source: data:,defaults%20%7B%0A%20%20%20%20path_checker%20tur%0A%20%20%20%20path_selector + %20%22round-robin%200%22%0A%20%20%20%20rr_weight%20uniform%0A%20%20%20%20prio%20const%0A + %20%20%20%20rr_min_io_rq%201%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20polling_interval + %2030%0A%20%20%20%20path_grouping_policy%20multibus%0A%20%20%20%20find_multipaths%20yes%0A + %20%20%20%20no_path_retry%20fail%0A%20%20%20%20user_friendly_names%20yes%0A%20%20%20%20failback + %20immediate%0A%20%20%20%20checker_timeout%2010%0A%20%20%20%20fast_io_fail_tmo%20off%0A%7D%0A%0Adevices + %20%7B%0A%20%20%20%20device%20%7B%0A%20%20%20%20%20%20%20%20path_checker%20tur%0A + %20%20%20%20%20%20%20%20product%20%22FlashSystem%22%0A%20%20%20%20%20%20%20%20vendor%20%22IBM%22%0A + %20%20%20%20%20%20%20%20rr_weight%20uniform%0A%20%20%20%20%20%20%20%20rr_min_io_rq + %204%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20path_grouping_policy + %20multibus%0A%20%20%20%20%20%20%20%20path_selector%20%22round-robin%200%22%0A + %20%20%20%20%20%20%20%20no_path_retry%20fail%0A%20%20%20%20%20%20%20%20failback%20immediate%0A + %20%20%20%20%7D%0A%20%20%20%20device%20%7B%0A%20%20%20%20%20%20%20%20path_checker%20tur%0A + %20%20%20%20%20%20%20%20product%20%22FlashSystem-9840%22%0A%20%20%20%20%20%20%20%20vendor%20%22IBM%22%0A + %20%20%20%20%20%20%20%20fast_io_fail_tmo%20off%0A%20%20%20%20%20%20%20%20rr_weight%20uniform%0A + %20%20%20%20%20%20%20%20rr_min_io_rq%201000%20%20%20%20%20%20%20%20%20%20%20%20%0A + %20%20%20%20%20%20%20%20path_grouping_policy%20multibus%0A%20%20%20%20%20%20%20%20path_selector + %20%22round-robin%200%22%0A%20%20%20%20%20%20%20%20no_path_retry%20fail%0A + %20%20%20%20%20%20%20%20failback%20immediate%0A%20%20%20%20%7D%0A%20%20%20%20device%20%7B%0A + %20%20%20%20%20%20%20%20vendor%20%22IBM%22%0A%20%20%20%20%20%20%20%20product%20%222145%22%0A + %20%20%20%20%20%20%20%20path_checker%20tur%0A%20%20%20%20%20%20%20%20features%20%221%20queue_if_no_path + %22%0A%20%20%20%20%20%20%20%20path_grouping_policy%20group_by_prio%0A + %20%20%20%20%20%20%20%20path_selector%20%22service-time%200%22%20%23%20Used%20by%20Red%20Hat%207.x%0A + %20%20%20%20%20%20%20%20prio%20alua%0A%20%20%20%20%20%20%20%20rr_min_io_rq%201%0A + %20%20%20%20%20%20%20%20rr_weight%20uniform%20%0A%20%20%20%20%20%20%20%20no_path_retry%20%225%22%0A + %20%20%20%20%20%20%20%20dev_loss_tmo%20120%0A%20%20%20%20%20%20%20%20failback%20immediate%0A%20%20%20%7D + %0A%7D%0A + verification: {} + - path: /etc/udev/rules.d/99-ibm-2145.rules + mode: 420 + filesystem: root + contents: + source: data:,%23%20Set%20SCSI%20command%20timeout%20to%20120s%20%28default%20%3D%3D + %2030%20or%2060%29%20for%20IBM%202145%20devices%0ASUBSYSTEM%3D%3D%22block%22%2C%20ACTION%3D%3D%22add + %22%2C%20ENV%7BID_VENDOR%7D%3D%3D%22IBM%22%2CENV%7BID_MODEL%7D%3D%3D%222145%22%2C%20RUN%2B%3D%22/bin/sh + %20-c%20%27echo%20120%20%3E/sys/block/%25k/device/timeout%27%22%0A + verification: {} + systemd: + units: + - name: multipathd.service + enabled: true + # Uncomment the following lines if this MachineConfig will be used with iSCSI connectivity + #- name: iscsid.service + # enabled: true + ``` + + Apply the yaml file. + ```bash + oc apply -f 99-ibm-attach.yaml + ``` + + RHEL users should verify that the `systemctl status multipathd` output indicates that the multipath status is active and error-free. + + ```bash + yum install device-mapper-multipath + modprobe dm-multipath + systemctl enable multipathd + systemctl start multipathd + systemctl status multipathd + multipath -ll + ``` + + #### 3. Configure storage system connectivity + 3.1. Define the hostname of each Kubernetes node on the relevant storage systems with the valid WWPN(for Fibre Channel) or IQN(for iSCSI) of the node. + + 3.2. For Fibre Channel, configure the relevant zoning from the storage to the host. + + ## Configuring k8s secret and storage class + In order to use the driver, create the relevant storage classes and secrets, as needed. + Note: This section can be done also after the operator installation. + + This section describes how to: + 1. Create a storage system secret - to define the storage system credentials (user and password) and its address. + 2. Configure the k8s storage class - to define the storage system pool name, secret reference, SpaceEfficiency (thin, compressed, or deduplicated) and fstype (xfs\ext4). + + #### 1. Create an array secret + Create a secret file as follows `array-secret.yaml` and update the relevant credentials: + + ``` + kind: Secret + apiVersion: v1 + metadata: + name: + namespace: + type: Opaque + stringData: + management_address: # Array management addresses + username: # Array username + data: + password: # Array password + ``` + + Apply the secret: + + ``` + $ kubectl apply -f array-secret.yaml + ``` + + To create the secret using a command line terminal, use the following command: + ```bash + kubectl create secret generic --from-literal=username= --fromliteral=password= --from-literal=management_address= -n + ``` + + #### 2. Create storage classes + + Create a storage class `storageclass-gold.yaml` file as follows, with the relevant capabilities, pool and, array secret. + + Use the `SpaceEfficiency` parameters for each storage system. These values are not case sensitive: + * IBM FlashSystem A9000 and A9000R + * Always includes deduplication and compression. No need to specify during configuration. + * IBM Spectrum Virtualize Family + * `thin` + * `compressed` + * `deduplicated` + * IBM DS8000 Family + * `standard` (default value, if not specified) + * `thin` + + ``` + kind: StorageClass + apiVersion: storage.k8s.io/v1 + metadata: + name: gold + provisioner: block.csi.ibm.com + parameters: + #SpaceEfficiency: # Optional: Values applicable for Spectrum Virtualize Family are: thin, compressed, or deduplicated + pool: # DS8000 Family paramater is VALUE_POOL_ID + + csi.storage.k8s.io/provisioner-secret-name: + csi.storage.k8s.io/provisioner-secret-namespace: + csi.storage.k8s.io/controller-publish-secret-name: + csi.storage.k8s.io/controller-publish-secret-namespace: + + csi.storage.k8s.io/fstype: xfs # Optional: Values ext4/xfs. The default is ext4. + volume_name_prefix: # Optional: DS8000 Family maximum prefix length is 5 characters. Maximum prefix length for other systems is 20 characters. + ``` + + #### 3. Apply the storage class: + + ```bash + $ kubectl apply -f storageclass-gold.yaml + storageclass.storage.k8s.io/gold created + ``` + + keywords: + - IBM + - BlockStorage + - CSI + version: 1.1.0 + replaces: ibm-block-csi-operator.v1.0.0 + maturity: stable + maintainers: + - name: Guang Jiong Lou + email: luogj@cn.ibm.com + minKubeVersion: 1.14.1 + provider: + name: IBM + links: + - name: Source Code + url: https://github.com/IBM/ibm-block-csi-operator + icon: + - base64data:  + mediatype: image/png + labels: + alm-owner-ibmblockcsi: ibmblockcsioperator + operated-by: ibmblockcsioperator + selector: + matchLabels: + alm-owner-ibmblockcsi: ibmblockcsioperator + operated-by: ibmblockcsioperator + installModes: + - type: OwnNamespace + supported: true + - type: SingleNamespace + supported: true + - type: MultiNamespace + supported: false + - type: AllNamespaces + supported: false + customresourcedefinitions: + owned: + - name: ibmblockcsis.csi.ibm.com + version: v1 + group: csi.ibm.com + kind: IBMBlockCSI + displayName: "IBM block storage CSI driver" + description: "Represents an block storage CSI driver" + resources: + - kind: ServiceAccount + name: '' + version: v1 + - kind: StatefulSet + name: '' + version: apps/v1 + - kind: DaemonSet + name: '' + version: apps/v1 + specDescriptors: + - description: Controller Image Repository. + displayName: Controller Image Repository + path: controller.repository + x-descriptors: + - 'urn:alm:descriptor:com.tectonic.ui:text' + - description: Controller Image Tag. + displayName: Controller Image Tag + path: controller.tag + x-descriptors: + - 'urn:alm:descriptor:com.tectonic.ui:text' + - description: Node Image Repository. + displayName: Node Image Repository + path: node.repository + x-descriptors: + - 'urn:alm:descriptor:com.tectonic.ui:text' + - description: Node Image Tag. + displayName: Node Image Tag + path: node.tag + x-descriptors: + - 'urn:alm:descriptor:com.tectonic.ui:text' + statusDescriptors: + - description: The current status of the driver. + displayName: Status + path: phase + x-descriptors: + - 'urn:alm:descriptor:io.kubernetes.phase' + - description: Is the controller ready? + displayName: Controller Ready + path: controllerReady + x-descriptors: + - 'urn:alm:descriptor:text' + - description: Is the node ready? + displayName: Node Ready + path: nodeReady + x-descriptors: + - 'urn:alm:descriptor:text' + - description: The current version of the driver. + displayName: Version + path: version + install: + strategy: deployment + spec: + clusterPermissions: + - serviceAccountName: ibm-block-csi-operator + rules: + - apiGroups: + - "" + resources: + - pods + verbs: + - get + - apiGroups: + - "" + resources: + - configmaps + verbs: + - get + - create + - delete + - apiGroups: + - "" + resources: + - secrets + verbs: + - get + - list + - apiGroups: + - "" + resources: + - persistentvolumeclaims + verbs: + - get + - list + - watch + - update + - apiGroups: + - "" + resources: + - persistentvolumes + verbs: + - get + - list + - watch + - update + - create + - delete + - patch + - apiGroups: + - "" + resources: + - events + verbs: + - '*' + - apiGroups: + - "" + resources: + - nodes + verbs: + - get + - list + - watch + - apiGroups: + - apps + resources: + - deployments + - daemonsets + - statefulsets + verbs: + - get + - list + - watch + - update + - create + - delete + - apiGroups: + - "" + resources: + - serviceaccounts + verbs: + - create + - delete + - get + - watch + - list + - apiGroups: + - rbac.authorization.k8s.io + resources: + - clusterroles + - clusterrolebindings + verbs: + - create + - delete + - get + - watch + - list + - apiGroups: + - storage.k8s.io + resources: + - volumeattachments + verbs: + - get + - list + - watch + - update + - patch + - apiGroups: + - storage.k8s.io + resources: + - storageclasses + verbs: + - get + - list + - watch + - apiGroups: + - monitoring.coreos.com + resources: + - servicemonitors + verbs: + - get + - create + - apiGroups: + - apps + resourceNames: + - ibm-block-csi-operator + resources: + - deployments/finalizers + verbs: + - update + - apiGroups: + - storage.k8s.io + resources: + - csidrivers + verbs: + - create + - delete + - get + - watch + - list + - apiGroups: + - storage.k8s.io + resources: + - csinodes + verbs: + - get + - list + - watch + - apiGroups: + - security.openshift.io + resourceNames: + - anyuid + - privileged + resources: + - securitycontextconstraints + verbs: + - use + - apiGroups: + - apiextensions.k8s.io + resources: + - customresourcedefinitions + verbs: + - create + - list + - watch + - delete + - apiGroups: + - csi.ibm.com + resources: + - '*' + verbs: + - '*' + deployments: + - name: ibm-block-csi-operator + spec: + replicas: 1 + selector: + matchLabels: + app.kubernetes.io/name: ibm-block-csi-operator + template: + metadata: + labels: + app.kubernetes.io/name: ibm-block-csi-operator + spec: + serviceAccountName: ibm-block-csi-operator + affinity: + nodeAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + nodeSelectorTerms: + - matchExpressions: + - key: kubernetes.io/arch + operator: In + values: + - amd64 + containers: + - name: ibm-block-csi-operator + resources: + requests: + memory: 50Mi + cpu: 50m + limits: + memory: 100Mi + cpu: 100m + readinessProbe: + exec: + command: ["./health_check.sh"] + initialDelaySeconds: 3 + periodSeconds: 1 + livenessProbe: + exec: + command: ["./health_check.sh"] + initialDelaySeconds: 10 + periodSeconds: 30 + securityContext: + capabilities: + drop: + - ALL + image: registry.connect.redhat.com/ibm/ibm-block-csi-operator:1.1.0 + imagePullPolicy: IfNotPresent + command: + - ibm-block-csi-operator + env: + - name: WATCH_NAMESPACE + value: "" + - name: POD_NAME + valueFrom: + fieldRef: + fieldPath: metadata.name + - name: OPERATOR_NAME + value: "ibm-block-csi-operator" diff --git a/deploy/olm-catalog/ibm-block-csi-operator/1.0.0/ibm-block-csi-operator.package.yaml b/deploy/olm-catalog/ibm-block-csi-operator/ibm-block-csi-operator.package.yaml similarity index 65% rename from deploy/olm-catalog/ibm-block-csi-operator/1.0.0/ibm-block-csi-operator.package.yaml rename to deploy/olm-catalog/ibm-block-csi-operator/ibm-block-csi-operator.package.yaml index 10fb50cae..526960214 100644 --- a/deploy/olm-catalog/ibm-block-csi-operator/1.0.0/ibm-block-csi-operator.package.yaml +++ b/deploy/olm-catalog/ibm-block-csi-operator/ibm-block-csi-operator.package.yaml @@ -1,5 +1,5 @@ packageName: ibm-block-csi-operator channels: - name: stable - currentCSV: ibm-block-csi-operator.v1.0.0 + currentCSV: ibm-block-csi-operator.v1.1.0 defaultChannel: stable diff --git a/deploy/operator.yaml b/deploy/operator.yaml index 88d017281..b16bf52d3 100644 --- a/deploy/operator.yaml +++ b/deploy/operator.yaml @@ -25,7 +25,7 @@ spec: annotations: productName: ibm-block-csi-operator productID: ibm-block-csi-operator - productVersion: "1.0.0" + productVersion: "1.1.0" spec: serviceAccountName: ibm-block-csi-operator affinity: @@ -60,7 +60,7 @@ spec: capabilities: drop: - ALL - image: ibmcom/ibm-block-csi-operator:1.0.0 + image: ibmcom/ibm-block-csi-operator:1.1.0 imagePullPolicy: IfNotPresent command: - ibm-block-csi-operator diff --git a/deploy/role.yaml b/deploy/role.yaml index 5a560fd14..0139ccd8c 100644 --- a/deploy/role.yaml +++ b/deploy/role.yaml @@ -51,6 +51,7 @@ rules: - update - create - delete + - patch - apiGroups: - "" resources: @@ -108,6 +109,7 @@ rules: - list - watch - update + - patch - apiGroups: - storage.k8s.io resources: @@ -149,6 +151,15 @@ rules: - get - list - watch +- apiGroups: + - security.openshift.io + resourceNames: + - anyuid + - privileged + resources: + - securitycontextconstraints + verbs: + - use - apiGroups: - apiextensions.k8s.io resources: diff --git a/hack/update-crds.sh b/hack/update-crds.sh new file mode 100755 index 000000000..272bbb4ea --- /dev/null +++ b/hack/update-crds.sh @@ -0,0 +1,28 @@ +#!/bin/bash -xe + +# +# Copyright 2019 IBM Corp. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +# Run operator-sdk generate k8s and operator-sdk generate openapi to update code after crd changes. + +if ! [ -x "$(command -v operator-sdk)" ]; then + echo 'Error: operator-sdk is not installed.' >&2 + exit 1 +fi + +operator-sdk generate k8s + +operator-sdk generate openapi diff --git a/hack/update-installer.sh b/hack/update-installer.sh index 0fa73403d..e54153197 100755 --- a/hack/update-installer.sh +++ b/hack/update-installer.sh @@ -41,7 +41,7 @@ function contains() echo "generate operator installer" -printf "# Code generated by update-copyright.sh. DO NOT EDIT.\n\n" > $TARGET_FILE +printf "# Code generated by $(basename $0). DO NOT EDIT.\n\n" > $TARGET_FILE for file_name in $(ls $CRD_PATH) do diff --git a/pkg/config/resources.go b/pkg/config/resources.go index 087915fbb..2bee109bb 100644 --- a/pkg/config/resources.go +++ b/pkg/config/resources.go @@ -37,6 +37,10 @@ const ( ExternalAttacherClusterRoleBinding ResourceName = "external-attacher-clusterrolebinding" ExternalSnapshotterClusterRole ResourceName = "external-snapshotter-clusterrole" ExternalSnapshotterClusterRoleBinding ResourceName = "external-snapshotter-clusterrolebinding" + CSIControllerSCCClusterRole ResourceName = "csi-controller-scc-clusterrole" + CSIControllerSCCClusterRoleBinding ResourceName = "csi-controller-scc-clusterrolebinding" + CSINodeSCCClusterRole ResourceName = "csi-node-scc-clusterrole" + CSINodeSCCClusterRoleBinding ResourceName = "csi-node-scc-clusterrolebinding" ) // GetNameForResource returns the name of a resource for a CSI driver diff --git a/pkg/config/settings.go b/pkg/config/settings.go index 0c8115ad5..d473da43a 100644 --- a/pkg/config/settings.go +++ b/pkg/config/settings.go @@ -22,8 +22,8 @@ const ( CSIAttacherImage = "quay.io/k8scsi/csi-attacher:v1.2.1" CSILivenessProbeImage = "quay.io/k8scsi/livenessprobe:v1.1.0" - ControllerTag = "1.0.0" - NodeTag = "1.0.0" + ControllerTag = "1.1.0" + NodeTag = "1.1.0" NodeAgentTag = "1.0.0" DefaultNamespace = "kube-system" diff --git a/pkg/controller/ibmblockcsi/ibmblockcsi_controller.go b/pkg/controller/ibmblockcsi/ibmblockcsi_controller.go index 9644707ce..22461f9bd 100644 --- a/pkg/controller/ibmblockcsi/ibmblockcsi_controller.go +++ b/pkg/controller/ibmblockcsi/ibmblockcsi_controller.go @@ -21,6 +21,7 @@ import ( "fmt" "os" "reflect" + "strings" "time" csiv1 "github.com/IBM/ibm-block-csi-operator/pkg/apis/csi/v1" @@ -79,7 +80,14 @@ func getServerVersion() (string, error) { return "", err } - return kubeutil.ServerVersion(kubeClient.Discovery()) + serverVersion, err := kubeutil.ServerVersion(kubeClient.Discovery()) + if err != nil { + return serverVersion, err + } + if strings.HasSuffix(serverVersion, "+") { + serverVersion = strings.TrimSuffix(serverVersion, "+") + } + return serverVersion, nil } // newReconciler returns a new reconcile.Reconciler @@ -333,11 +341,15 @@ func (r *ReconcileIBMBlockCSI) reconcileClusterRole(instance *ibmblockcsi.IBMBlo externalProvisioner := instance.GenerateExternalProvisionerClusterRole() externalAttacher := instance.GenerateExternalAttacherClusterRole() + controllerSCC := instance.GenerateSCCForControllerClusterRole() + nodeSCC := instance.GenerateSCCForNodeClusterRole() //externalSnapshotter := instance.GenerateExternalSnapshotterClusterRole() for _, cr := range []*rbacv1.ClusterRole{ externalProvisioner, externalAttacher, + controllerSCC, + nodeSCC, //externalSnapshotter, } { if err := controllerutil.SetControllerReference(instance.Unwrap(), cr, r.scheme); err != nil { @@ -371,11 +383,15 @@ func (r *ReconcileIBMBlockCSI) reconcileClusterRoleBinding(instance *ibmblockcsi externalProvisioner := instance.GenerateExternalProvisionerClusterRoleBinding() externalAttacher := instance.GenerateExternalAttacherClusterRoleBinding() + controllerSCC := instance.GenerateSCCForControllerClusterRoleBinding() + nodeSCC := instance.GenerateSCCForNodeClusterRoleBinding() //externalSnapshotter := instance.GenerateExternalSnapshotterClusterRoleBinding() for _, crb := range []*rbacv1.ClusterRoleBinding{ externalProvisioner, externalAttacher, + controllerSCC, + nodeSCC, //externalSnapshotter, } { if err := controllerutil.SetControllerReference(instance.Unwrap(), crb, r.scheme); err != nil { diff --git a/pkg/controller/ibmblockcsi/syncer/csi_controller.go b/pkg/controller/ibmblockcsi/syncer/csi_controller.go index f8d9b466d..532441ae3 100644 --- a/pkg/controller/ibmblockcsi/syncer/csi_controller.go +++ b/pkg/controller/ibmblockcsi/syncer/csi_controller.go @@ -134,14 +134,16 @@ func (s *csiControllerSyncer) ensureContainersSpec() []corev1.Container { // csi provisioner sidecar provisioner := s.ensureContainer(provisionerContainerName, s.getCSIProvisionerImage(), - []string{"--csi-address=$(ADDRESS)", "--v=5"}, + // TODO: make timeout configurable + []string{"--csi-address=$(ADDRESS)", "--v=5", "--timeout=30s"}, ) provisioner.ImagePullPolicy = s.getCSIProvisionerPullPolicy() // csi attacher sidecar attacher := s.ensureContainer(attacherContainerName, s.getCSIAttacherImage(), - []string{"--csi-address=$(ADDRESS)", "--v=5"}, + // TODO: make timeout configurable + []string{"--csi-address=$(ADDRESS)", "--v=5", "--timeout=30s"}, ) attacher.ImagePullPolicy = s.getCSIAttacherPullPolicy() diff --git a/pkg/controller/ibmblockcsi/syncer/csi_node.go b/pkg/controller/ibmblockcsi/syncer/csi_node.go index f7b8aabc6..3eb7db296 100644 --- a/pkg/controller/ibmblockcsi/syncer/csi_node.go +++ b/pkg/controller/ibmblockcsi/syncer/csi_node.go @@ -97,6 +97,7 @@ func (s *csiNodeSyncer) ensurePodSpec() corev1.PodSpec { Containers: s.ensureContainersSpec(), Volumes: s.ensureVolumes(), HostIPC: true, + HostNetwork: true, ServiceAccountName: config.GetNameForResource(config.CSINodeServiceAccount, s.driver.Name), Affinity: s.driver.Spec.Node.Affinity, Tolerations: s.driver.Spec.Node.Tolerations, @@ -266,6 +267,14 @@ func (s *csiNodeSyncer) getVolumeMountsFor(name string) []corev1.VolumeMount { MountPath: "/host", MountPropagation: &mountPropagationB, }, + { + Name: "lib-modules", + MountPath: "/lib/modules", + }, + { + Name: "iscsi", + MountPath: "/etc/iscsi", + }, } case nodeDriverRegistrarContainerName: @@ -299,6 +308,8 @@ func (s *csiNodeSyncer) ensureVolumes() []corev1.Volume { ensureVolume("device-dir", ensureHostPathVolumeSource("/dev", "Directory")), ensureVolume("sys-dir", ensureHostPathVolumeSource("/sys", "Directory")), ensureVolume("host-dir", ensureHostPathVolumeSource("/", "Directory")), + ensureVolume("lib-modules", ensureHostPathVolumeSource("/lib/modules", "Directory")), + ensureVolume("iscsi", ensureHostPathVolumeSource("/etc/iscsi", "Directory")), } } diff --git a/pkg/internal/ibmblockcsi/static_resource_generator.go b/pkg/internal/ibmblockcsi/static_resource_generator.go index f9aa2d36b..5f0646337 100644 --- a/pkg/internal/ibmblockcsi/static_resource_generator.go +++ b/pkg/internal/ibmblockcsi/static_resource_generator.go @@ -157,7 +157,7 @@ func (c *IBMBlockCSI) GenerateExternalAttacherClusterRole() *rbacv1.ClusterRole { APIGroups: []string{""}, Resources: []string{"persistentvolumes"}, - Verbs: []string{"get", "list", "watch", "update"}, + Verbs: []string{"get", "list", "watch", "update", "patch"}, }, { APIGroups: []string{c.GetCSIAPIGroup()}, @@ -172,7 +172,7 @@ func (c *IBMBlockCSI) GenerateExternalAttacherClusterRole() *rbacv1.ClusterRole { APIGroups: []string{"storage.k8s.io"}, Resources: []string{"volumeattachments"}, - Verbs: []string{"get", "list", "watch", "update"}, + Verbs: []string{"get", "list", "watch", "update", "patch"}, }, }, } @@ -273,6 +273,78 @@ func (c *IBMBlockCSI) GenerateExternalSnapshotterClusterRoleBinding() *rbacv1.Cl } } +func (c *IBMBlockCSI) GenerateSCCForControllerClusterRole() *rbacv1.ClusterRole { + return &rbacv1.ClusterRole{ + ObjectMeta: metav1.ObjectMeta{ + Name: config.GetNameForResource(config.CSIControllerSCCClusterRole, c.Name), + }, + Rules: []rbacv1.PolicyRule{ + { + APIGroups: []string{"security.openshift.io"}, + Resources: []string{"securitycontextconstraints"}, + ResourceNames: []string{"anyuid"}, + Verbs: []string{"use"}, + }, + }, + } +} + +func (c *IBMBlockCSI) GenerateSCCForControllerClusterRoleBinding() *rbacv1.ClusterRoleBinding { + return &rbacv1.ClusterRoleBinding{ + ObjectMeta: metav1.ObjectMeta{ + Name: config.GetNameForResource(config.CSIControllerSCCClusterRoleBinding, c.Name), + }, + Subjects: []rbacv1.Subject{ + { + Kind: "ServiceAccount", + Name: config.GetNameForResource(config.CSIControllerServiceAccount, c.Name), + Namespace: c.Namespace, + }, + }, + RoleRef: rbacv1.RoleRef{ + Kind: "ClusterRole", + Name: config.GetNameForResource(config.CSIControllerSCCClusterRole, c.Name), + APIGroup: "rbac.authorization.k8s.io", + }, + } +} + +func (c *IBMBlockCSI) GenerateSCCForNodeClusterRole() *rbacv1.ClusterRole { + return &rbacv1.ClusterRole{ + ObjectMeta: metav1.ObjectMeta{ + Name: config.GetNameForResource(config.CSINodeSCCClusterRole, c.Name), + }, + Rules: []rbacv1.PolicyRule{ + { + APIGroups: []string{"security.openshift.io"}, + Resources: []string{"securitycontextconstraints"}, + ResourceNames: []string{"privileged"}, + Verbs: []string{"use"}, + }, + }, + } +} + +func (c *IBMBlockCSI) GenerateSCCForNodeClusterRoleBinding() *rbacv1.ClusterRoleBinding { + return &rbacv1.ClusterRoleBinding{ + ObjectMeta: metav1.ObjectMeta{ + Name: config.GetNameForResource(config.CSINodeSCCClusterRoleBinding, c.Name), + }, + Subjects: []rbacv1.Subject{ + { + Kind: "ServiceAccount", + Name: config.GetNameForResource(config.CSINodeServiceAccount, c.Name), + Namespace: c.Namespace, + }, + }, + RoleRef: rbacv1.RoleRef{ + Kind: "ClusterRole", + Name: config.GetNameForResource(config.CSINodeSCCClusterRole, c.Name), + APIGroup: "rbac.authorization.k8s.io", + }, + } +} + func (c *IBMBlockCSI) GetCSIAPIGroup() string { if c.ServerVersion == "1.13" { return "csi.storage.k8s.io" diff --git a/version/version.go b/version/version.go index 247c1b1d3..144303d5e 100644 --- a/version/version.go +++ b/version/version.go @@ -17,6 +17,6 @@ package version var ( - Version = "1.0.0" - DriverVersion = "1.0.0" + Version = "1.1.0" + DriverVersion = "1.1.0" )