From e875ba4654962f73eace56b2aecad332dd64f28d Mon Sep 17 00:00:00 2001 From: Nybble <30316687+NybbleHub@users.noreply.github.com> Date: Fri, 7 Jan 2022 05:57:26 +0100 Subject: [PATCH] Certs faq (#182) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * Add new documentations to helm-charts repo (#1) * Add new documentations to helm-charts repo * Replace devops with helm charts keywords * Grammar improvements * Update README * Add issue templates and fix readme typos (#3) * Add issue templates and fix readme typos * Replace component name with chart name * Replace OS/Version to the Helm/Kube versions * Replace OS/Version to the Helm/Kube versions * Migrate helm charts from opensearch-devops repo (#7) * Adding a new folder to host Helm related code * Helm Chart for OpenSearch (#4) * Create basic structure of OpenSearch helm chart * Add templates and change values * Change statefulset and configmap to resolve indentation issue * Fix issues in templates * Fix typos in statefulset.yaml * Add multinode deployment feature * Update version to reflect the OpenSearch version * Add explicit security configuration * Update values.yaml * Create placeholder README.md * Minimum masters should be 3 * Add YAML support for config. sysctl vm.mem fix. * Fixing PSP. Adding better sysctl logic. * Adding ref for systctl * PSP False by default * Disable HTTP SSL by default for Demo. * Fix Chart version to sync with OpenSearch Version * Change cluster name and enable SSL by default Co-authored-by: Aaron Layfield * fix: give networkpolicy objects a unique name (#16) This fixes the problem of installing this chart multiple times in the same namespace and having the network policy name conflict. * fix: use the stable chart appVersion as image tag by default (#17) Using :latest by default is going to lead to clusters with version skew as pods schedule onto new nodes. So use a stable tag instead. * OpenSearch Dashboards Helm Chart (#10) * Scaffold OpenSearch Dashboards Helm Chart * Fix error for connection refused * Add RBAC functionality * Add security configurations in the chart * Address issues and comments * Fix templates * Disable SSL by default * Address comments for beautification * Address comments * chore: update demo config section (#24) This snippet doesn't make sense in a kubernetes statefulset. * added secretMounts to values.yaml w/ example config (#29) Co-authored-by: johannes.reppin * Change persistence config to make it more coherent w/ other helm charts (#33) Co-authored-by: johannes.reppin * add Volumes and change broken (!) yaml indentation (#31) Co-authored-by: johannes.reppin * support for current ingress apiVersion (#47) * Helm Chart Fixes for Env variables and volumes (#35) * Helm Chart Fixes for Env variables and volumes The opensearch-dashboards chart failed to render correctly when utilizing the extraEnvs flag, caused by incorrect indentation. The opensearch chart failed to render when utlizing the secrets for the security config, this was due to them being in the env section. This pull request reqolves both issues, verified via running helm template with the minumal values files included here: ```yaml envFrom: - secretRef: name: kibana-secrets extraEnvs: - name: TENANT_ID valueFrom: secretKeyRef: name: kibana-secrets key: tenantID ``` ```yaml securityConfig: enabled: true configSecret: "security-config" internalUsersSecret: "internal-users-config" rolesMappingSecret: "roles-mapping-config" rolesSecret: "roles-config" ``` * Updating paths in sts to be dynamic Updating the paths specified in the sts for opensearch to utilize .Values.opensearchHome to allow for dynamic paths, with a default of `/usr/share/opensearch` which should be sufficient for most users. * Fixing config path in opensearch-dashboards (#38) * Fixing config path in opensearch-dashboards The manifests rendered by the Helm chart place the user provided config into the incorrect directory. This simply updates that location to the correct path and updates the values.yaml file to use the correct default config file so that the user provided setting override the defaults. * Updating cert paths to opensearch-dashboards Cert paths also need to utilize new filesystem location for opensearch-dashboards config. * Resolves issue with securityConfig path (#41) * Resolves issue with securityConfig path Issue #39 This updates the securityConfig path in values to use the correct value for opensearch. * Fixing bad auto formatting Removing unneeded indentation/newlines. * Fixing missed auto formatting errors * resolve issue about .Values.opensearchHome (#52) refer to this: https://github.com/opensearch-project/opensearch-devops/commit/fe831db949469cd74111f33036d37f1717135329#commitcomment-55395428 Error Msg: nil pointer evaluating interface {}.opensearchHome * Fix helm chart can not be deployed without ssl (#56) * Fixing issue exposed by changes in #38 After switching the name of the config file, and removing the shadowing between the default (from the docker container opensearch-dashbaords.yaml) and the default from the helm chart (dashboards.yaml) there is an issue with the certs that are attempting to be used. In order for this to work with the defaults, disabled TLS verification will be needed, and then disabling TLS to remain in line with the defaults. I added a commented out section showing what could potentially be used as TLS config if the user chooses to enable it. * Using conventional yaml formatting for ssl config Moving comments around to follow relevant code and utilizing nested yaml format rather than dot format. * Changing Folder name to Charts * Change deafult configuration for dashboards * Update securityconfig.yaml to remove extra spaces Co-authored-by: Barani Co-authored-by: Aaron Layfield Co-authored-by: Scott Leggett Co-authored-by: Johannes Reppin Co-authored-by: johannes.reppin Co-authored-by: paltryeffort Co-authored-by: hgoscenski-imanage <77067840+hgoscenski-imanage@users.noreply.github.com> Co-authored-by: Nagle Zhang * chore: remove redundant line from yaml (#18) * fix: remove buggy labels template (#20) The opensearch-dashboards.standard did not properly escape chart version, and anyway we should be using the same set of standard labels as all the other templates. * fix: use absolute path to opensearch-keystore binary (#27) It is not in $PATH. * chore: use consistent indentation in opensearch templates (#24) * Fix typo in comment (#10) * fix: make secretMount parameters required (#22) This fixes the case where a parameter on one of the items is silently missing. * fix: avoid line containing only spaces in rendered template (#23) * fix!: update name of JAVA_OPTS variable (#39) ES_JAVA_OPTS has been renamed in Opensearch to OPENSEARCH_JAVA_OPTS. * chore: use consistent indentation in opensearch-dashboards templates (#25) * Add TheAlgo and DandyDeveloper as the new maintainers of the repo (#47) * Add DandyDeveloper as the new maintainer of the repo * Add TheAlgo as part of the maintainer list * Modify majorVersion fallback logic (#21) * feat: modify majorVersion fallback logic * Look in both .Values.imageTag and .Chart.AppVersion before falling back to a default value. * Use the built-in semver parsing function. * Don't ignore the version for non-opensearch images. * fix: use fallback major version 1 instead of 7 Opensearch is currently version 1.x. 7 seems to be a remnant of Elasticsearch. * fix securityConfigSecrets.config.data secrets mount plus permissions (#9) Fix securityConfigSecrets.config.data secrets mount plus permissions * Add README for OpenSearch (#48) * Add README for OpenSearch * Address comments * Add support for Helm chart linting and releasing. (#46) * - Added support for the Helm chart testing action. - Added support for the Helm chart releaser action. - Fixed minor lint issues in Helm chart values files. * Added support for testing in addition to linting. * - Relaxed event triggers on GitHub actions workflow for lint and test. - Now using `ubuntu-latest` for GitHub runner references. - Added `maintainers` to all charts. - Incremented patch version for each chart. * - Added title for Installation * - Added missing helm update step in installation. * fix: use consistent k8s API semver comparison logic (#19) This is required to work around bugs in the version string returned by kubernetes distros such as EKS and GKE, where they have invalid Semantic Version strings. See https://github.com/helm/helm/issues/3810. * Fix README.md (#60) * Enable Helm chart release (#61) * - Added change logs for the opensearch and opensearch-dashboards Helm charts. - Amended README files to reflect the intended installation and usage. - Incremented the version numbers to 1.0.2 for both Helm charts in adherence to linting rules and Semver 2. * - Modified OpenSearch chart description * - Reverted to previous chart installation instructions until we can verify the new method succeeds. * Helm Chart Releaser Trigger Fix (#73) * - Incremented Helm charts to ensure the releaser workflow triggers a difference. * - Added the `workflow_dispatch` option for manually pushing action workflows. * Remove stale README (#57) * Incorrect indentation for `extraVolumeMounts`, `extraEnvs`, `envFrom` in `statefulset.yaml`. (#80) * Changes - Fixes incorrect indentation for `extraVolumeMounts`, `extraEnvs`, and `envFrom`. * Changes: - Increment version of the opensearch dashboards chart until PR #75 is merged. * - Amended CHANGELOGs * enable setting docker registry for all images (#70) * Added basic support for plugins on nodes (#71) * Adding support for plugins & Prometheus support. * Updated annotations * Add support for plugin installation * Bumping chart patch. * Bumping again post merge with origin * Linting fixes. * Adding to CI. Updating changelog. * Possibly fixing linting issues. * Updating plugin * Increment chart again * Bumping chart patch. * CHANGELOG Updates * Use the correct master configuration for majorVersion 1 (#69) * fix: use the correct master configuration for majorversion 1 * chore: bump opensearch chart version * Amended installation instructions (#81) * Amended installation instruction and relaxed linting and testing workflow triggers. * Minor typographic error. * - Reverted linting and testing trigger globbing. * - Added path globbing. * - Removed path globbing. * Revert "- Amended CHANGELOGs" This reverts commit e0ab1787c5e5adecc7875c4908eeb11f2ad3214c. * - Bumped chart versions. - Amended CHANGELOGs. * Incremented opensearcn chart version to 1.0.8 * - Added specific references to the underlying charts folder from the root-level README. - Addressed clarifications from @TheAlgo. * - Modified change log for the OpenSearch Helm chart. * Use a per-install name for securityconfig secret (#41) * feat: per-install name for securityconfig secret Give the securityconfig secret an autogenerated unique name to facilitate installing the chart multiple times in the same namespace. This helps with the common case of sharing the securityconfig between multiple instantiations of this chart to construct an Opensearch cluster. * feat: update logic to handle externally defined secrets See the comments describing how this is intended to work. * chore: bump opensearch chart version * chore: add securityConfig to README * Rework labels in Opensearch chart to match standard recommendations (#37) * feat: rework labels to match standard recommendations https://helm.sh/docs/chart_best_practices/labels/#standard-labels https://kubernetes.io/docs/concepts/overview/working-with-objects/common-labels/ * chore: bump opensearch chart version * Add missing helm install commands in README (#90) * Adding a DCO Check related workflow (#101) * add missing labels key into roles.yaml (#99) * add missing labels key into roles.yaml * Apply suggestions from code review Co-authored-by: Oliver Hartl Co-authored-by: Oliver Hartl * fix: fix env and envFrom indentation when using keystore value. (#103) * fix: fix env and envFrom indentation when using keystore value. * fix: Chart version bump needed by CI * FIX: Issue 105 - RBAC enabled (#106) * - Added missing `labels:` stanza delimeter to role.yaml to address the failure when RBAC is enabled. * - Renamed CI values file for testing RBAC enabled. * - Indented template line to asthetically match. * - Incremented OpenSearch chart version to 1.2.2 to accommodate another PR. * - Amended CHANGELOG as per review. * Add option to disable initContainer chown update (#102) * Add option to disable initContainer chown update * True default, not false. * Remove trailing spaces * Updating CHANGELOG and README * Change appVersion of OpenSearch and Dashboards chart (#114) * Updating Latest API Versions for Ingress and Pod Policies (#94) * Updating Latest API Versions for Ingress and Pod Policies * chart version bump * 1.21 for Policy APIs * Attempting to use kind + GHA matrix for testing various k8s versions Co-authored-by: Aaron Layfield Co-authored-by: Dhiraj Kumar Jain * Fix deprication warnings about node.roles. Now roles described as a list (#124) * add values for fsgroup-volume image (#127) * add values for fsgroup-volume image * Increment the Chart version and update the Changelog * Add version 1.3.1 to CHANGELOG.md * fix: Handle log4j2 not being yaml (#110) and chart bump. (#123) * fix: Handle log4j2 not being yaml (#110) and chart bump. * Including tpl changes * Adding log4j example. * Adding some documentation AND updated per comment.s * Use project name and clarify from/to. * Explicitly document that config must be YAML multiline strings. * Cast as string for use with tpl. * Because this would be really annoying. * fix: Handle log4j2 not being yaml (#110) and chart bump to 1.4.0. Co-authored-by: Aaron Layfield * [Dashboards] Add extraVolumes and extraVolumeMounts (#128) * Remove whitespace in DN (#130) * Update Chart.yaml * Remove whitespace in dn. * update changelog. * update changelog and chart version. * Updating the copyright header to reflect the apache-2.0 license (#134) * Updating the copyright header to reflect the apache-2.0 license * Update opensearch dashboards version and changelogs Co-authored-by: Peter Zhu * Fix node.roles environment variable (#137) * Fix node.roles environment variable * forgotten version bump * Fix url to values.yaml in README.md in opensearch chart (#139) * Fix url to values.yaml in README.md in opensearch chart * Make URL to values.yaml in README.md more consistent (with reference section) * Increment the Chart version and update the Changelog * Update version of opensearch chart after resolving merge conflict Co-authored-by: Dmytro Gorbunov * FEATURE: Add support for IngressClassName (#149) * Added support for the `ingressClassName` field. The `kubernetes.io/ingress.class` annotation was deprecated in Kubernetes 1.18. * - Fixed trailing spaces as per chart lint rules. * docs: fix typo (#152) * docs: fix typo * Bump version * Add changelog * Add changelog Co-authored-by: Peter Zhu * Removed root-level CHANGELOG.md since each chart maintains their own (#165) changelog. * Change helm notes as the pod label key has changed (#148) * Change helm notes as the pod label key has changed * bump version * update CHANGELOG.md * resolve conflicts * bump version & update changelog * fix: deprecated api migration versions (#162) build: add changelog & bump version * Updated OpenSearch appVersion to 1.2.1 (#164) * Updated OpenSearch appVersion to 1.2.0 * Fixed CHANGELOG.MD * Updated to OpenSearch 1.2.1 * Fixed version Co-authored-by: Derek Diaz * prefer .Chart.AppVersion by default (#175) Do not specify `imageTag` in the default `values.yaml` to use .Chart.AppVersion by default Fixes #177 * Add notes about default install in README Signed-off-by: Sébastien Lehuédé * Add notes about default install in README Signed-off-by: Sébastien Lehuédé * Change version number * Change version number Signed-off-by: Peter Zhu * Remove additional files Signed-off-by: Peter Zhu * Remove additional files Signed-off-by: Peter Zhu Co-authored-by: Peter Zhu Co-authored-by: Dhiraj Kumar Jain Co-authored-by: Barani Co-authored-by: Aaron Layfield Co-authored-by: Scott Leggett Co-authored-by: Johannes Reppin Co-authored-by: johannes.reppin Co-authored-by: paltryeffort Co-authored-by: hgoscenski-imanage <77067840+hgoscenski-imanage@users.noreply.github.com> Co-authored-by: Nagle Zhang Co-authored-by: Avery Khoo <1571427+averykhoo@users.noreply.github.com> Co-authored-by: alborotogarcia <59288789+alborotogarcia@users.noreply.github.com> Co-authored-by: Michael Primeaux Co-authored-by: Kenan Erdogan Co-authored-by: Oliver Hartl Co-authored-by: Paul LESUR Co-authored-by: Hayden Fuss Co-authored-by: Sebor Co-authored-by: Kersten Schlosser <46895196+erbzn@users.noreply.github.com> Co-authored-by: sastorsl Co-authored-by: Rémi BUTET Co-authored-by: sebas-intellegens <55788126+sebas-intellegens@users.noreply.github.com> Co-authored-by: Barani <70038446+bbarani@users.noreply.github.com> Co-authored-by: Tomas Odehnal <62995026+tomasodehnal@users.noreply.github.com> Co-authored-by: Dmytro Gorbunov Co-authored-by: Dmytro Gorbunov Co-authored-by: Michael Kriese Co-authored-by: davidshtian Co-authored-by: Michael Rödel Co-authored-by: Derek Diaz Correa Co-authored-by: Derek Diaz Co-authored-by: K3A Co-authored-by: Peter Zhu --- README.md | 13 +++++++++++++ charts/opensearch/CHANGELOG.md | 16 ++++++++++++++-- charts/opensearch/Chart.yaml | 2 +- 3 files changed, 28 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index afe6a96d..0ba90c6a 100644 --- a/README.md +++ b/README.md @@ -42,6 +42,19 @@ helm install my-deployment opensearch/ Please see the `README.md` in the [OpenSearch](charts/opensearch) and [OpenSearch Dashboards](charts/opensearch-dashboards) directories for installation instructions. +### Notes About Default Installation + +By default, on startup, the `install_demo_configuration.sh` is runned via the `opensearch-docker-entrypoint.sh` script if `DISABLE_INSTALL_DEMO_CONFIG` is not `true`. + +In case custom certificates are used and `allow_unsafe_democertificates` is set to `false` in the configuration, this can prevent pods to start with the following error: `Demo certificates found but plugins.security.allow_unsafe_democertificates is set to false.` + +This can be solved by adding an environment variable in the `value.yml`: +``` +extraEnvs: + - name: DISABLE_INSTALL_DEMO_CONFIG + value: "true" +``` + ## Change Logs Please review the [OpenSearch](charts/opensearch/CHANGELOG.md) and the diff --git a/charts/opensearch/CHANGELOG.md b/charts/opensearch/CHANGELOG.md index 867e8eb4..4f6d3bf9 100644 --- a/charts/opensearch/CHANGELOG.md +++ b/charts/opensearch/CHANGELOG.md @@ -12,8 +12,17 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Removed ### Fixed ### Security ---- +--- +## [1.5.8] +### Added +- Added certs faqs in the opensearch documentations +### Changed +### Deprecated +### Removed +### Fixed +### Security +--- ## [1.5.7] ### Added ### Changed @@ -277,7 +286,10 @@ config: ### Fixed ### Security -[Unreleased]: https://github.com/opensearch-project/helm-charts/compare/opensearch-1.5.5...HEAD +[Unreleased]: https://github.com/opensearch-project/helm-charts/compare/opensearch-1.5.8...HEAD +[1.5.8]: https://github.com/opensearch-project/helm-charts/compare/opensearch-1.5.7...opensearch-1.5.8 +[1.5.7]: https://github.com/opensearch-project/helm-charts/compare/opensearch-1.5.6...opensearch-1.5.7 +[1.5.6]: https://github.com/opensearch-project/helm-charts/compare/opensearch-1.5.5...opensearch-1.5.6 [1.5.5]: https://github.com/opensearch-project/helm-charts/compare/opensearch-1.5.4...opensearch-1.5.5 [1.5.4]: https://github.com/opensearch-project/helm-charts/compare/opensearch-1.5.3...opensearch-1.5.4 [1.5.3]: https://github.com/opensearch-project/helm-charts/compare/opensearch-1.5.2...opensearch-1.5.3 diff --git a/charts/opensearch/Chart.yaml b/charts/opensearch/Chart.yaml index 6f7b0cae..f72ac52b 100644 --- a/charts/opensearch/Chart.yaml +++ b/charts/opensearch/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 1.5.7 +version: 1.5.8 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to